• Bug#1054585: phpmyadmin: no cleanup of tmp dir

    From William Desportes@21:1/5 to All on Sun Feb 11 14:50:01 2024
    This is an OpenPGP/MIME signed message (RFC 4880 and 3156)

    Hello Florian !


    But as we hardened our server, we setup an own php-fpm pool for
    phpmyadmin and
    changed the save_path to /var/lib/phpmyadmin/tmp. It seems like that it
    is our
    own created problem and we do need scripting on our end to clean these
    files ;)

    As I was re-reading this, be sure to not use the same directory as the
    tmp directory of phpMyAdmin.
    - It could get wiped out at any time
    - Some phpMyAdmin code can access it and leak sessions

    This will get better with phpMyAdmin 6.0, see: https://bugs.debian.org/bug=583588
    Most probably I will try to process this bug report while packaging
    phpMyAdmin 6.0.

    But be sure the directory is not in open_basedir for security reasons
    that will be better.

    At least this part of the bug report is actually valid ;)

    Indeed

    --
    William

    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEExNkf3872tKPGU/14kKDvG4JRqIkFAmXIzRQACgkQkKDvG4JR qInDKw//U2RCgRG2RpF6Zvl2eGkCJUAZGn7yxS9cZ23H+5QA85MJ4V0h0Q8dL83l M0mf0D/Z5kI1ea+fuuTfsrAqgOnNgcJEkcoBMxtinJWktMk1EE1PR3pWxOfQFlMo Y2tAFdRc1UpoKR7YZf2bm7vkxspKLC5VNt0uu26iE5QKg3/OkJD58vpjAZXfFjjz 0bZcEE9c3SK/cK696cEvf19zvIUCf9QDPclwfJF+n8p+buI5W3HXM3FQ/XHrSXJ0 vMLcKpYi1gdNJcPCC5TzQZtGLVRiZFM14s9pgPDi9FrcoUmgsLI7HNFBhv2WGkHH Gsjr99zmLunz9DXA0g8Mp2T6Z3Zzi1Ud4HhmmAN3fsXpv9FPjNnYg5KrNXJA6gub nbrEYI18OjLovVsneuKU9uWugpTC6SWJH0N5FZ/oAlwFt4eBv3kno0Ny+as5/Gmy Is6axcaRtVQNCZEQNAOdZlL/KOOmuAK+5XvEfhUmoiVW3w+eUY5WqSrGMVGUFVrc wqvUxy8AAs5EYQucymbGf1WqKgwd8JY6Rwz+APA2ModZLQa533PzEaaX4FWjg4EG 6OLmBm3YfowvuUouFmpiich3cWbGzUNsvog7MJGKng9aQVad+kxLIDYSu7dlq09P wpaLbSGtd74N3cZKqkBkhSgvuLuHgVRJ6B73E7dsc+UFEyB9LiE=
    =MXg3
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)