php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #23236 move_uploaded_file corrupts images
Submitted: 2003-04-16 02:16 UTC Modified: 2003-04-22 17:07 UTC
Votes:5
Avg. Score:4.0 ± 1.5
Reproduced:5 of 5 (100.0%)
Same Version:4 (80.0%)
Same OS:3 (60.0%)
From: dan at GARBAGE dot highspeedlink dot net Assigned:
Status: Not a bug Package: *General Issues
PHP Version: 4.3.1 OS: Linux 2.4.18-14 RedHat 8
Private report: No CVE-ID: None
 [2003-04-16 02:16 UTC] dan at GARBAGE dot highspeedlink dot net
(remove GARBAGE to reply, or it gets feed into the spamtrap)

Can anybody explain what's happening to perfectly good images passing through http://admin.highspeedlink.net/PHP/ for me?  The code for the page is available at http://admin.highspeedlink.net/PHP/source.txt for your perusal.  I've tested with MSIE 6.0 and Mozilla 1.4a on Windows, so this doesn't seem to be browser-specific.  Also, running dos2unix, unix2dos, etc. doesn't seem to help.

Considering what suggestions I've seen thus far, I'm thinking this is a bug, possibly related to character encoding, in move_uploaded_file().  Can people test this out and see how deadly it really is?

Warning for the squeamish: the linked page allows uploading of arbitrary images up to 100 [decimal] KB in size, and displays the last uploaded image.  No promises on what will or won't be there when you look.  Just upload only pictures of http://www.google.com/images?q=flowers and such, okay?  Feel free to upload arbitrary binary data and access it directly, as well--no filetype restrictions are in place.

This is not a localized copy of Apache, and thus #11066 does not apply.  (Indeed, my Apache 2.0.43 doesn't even recognize the CharsetRecodeMultipartForm directive.)

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2003-04-17 01:16 UTC] magnus@php.net
Please try using this CVS snapshot:

  http://snaps.php.net/php4-STABLE-latest.tar.gz
 
For Windows:
 
  http://snaps.php.net/win32/php4-win32-STABLE-latest.zip

and that link to the source code of the script gives a 
permission denied error. 
 [2003-04-17 13:13 UTC] dan at GARBAGE dot highspeedlink dot net
My apologies--FollowSymLinks got smashed in the config at some point.  See if you can see any obvious problems before I recompile PHP yet again, please?

PHPInfo page added at http://admin.highspeedlink.net/PHP/info.php for your edification.
 [2003-04-21 12:37 UTC] sniper@php.net
You're doing something wrong.

 [2003-04-22 16:27 UTC] dan at GARBAGE dot highspeedlink dot net
<P>Thanks, sniper, very helpful.  Ooh, let's see, do I:</P>
<P><OL><LI>Change the <I>./configure</I> options for PHP?</LI>
<LI>Modify <I>httpd.conf</I> in some way?</I></LI>
<LI>Recompile my kernel?</LI></OL>
or, secret option number four:<BR>
Do whatever I'm doing wrong, <I>differently</I>.</P>
<B>Great</B> idea, buddy.  Where do I sign up?</P>
<P>Does anybody have any <U>real</U> suggestions for how to go about fixing this?</P>
 [2003-04-22 16:30 UTC] dan at GARBAGE dot highspeedlink dot net
Using the justification, "You're doing something wrong," to change the status to "Bogus" is itself bogus.

Say, "I can't reproduce it with the linked script," or, "That script has a bug in it," or, "You're right, that's a bug of some sort."  Don't just be a pedantic ass about it.

Sorry, but sniper@php.net got on my nerves.  Does anyone have any valid insight into this issue?
 [2003-04-22 17:07 UTC] rasmus@php.net
This is not a support forum and Apache2 is not an officially supported web server for PHP at this point.  Try this with Apache1 and PHP 4.3 and if you can still reproduce it, let us know.  Otherwise your problem is not in PHP.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 18:00:01 2026 UTC