[drupal-devel] 4.5.2 Image module, PHP exec, SELinux problems

Djun Kim puregin at puregin.org
Mon Apr 18 19:46:34 UTC 2005



    is anyone else running Drupal on Fedora FC3 or any other system
implementing targeted policy for Security Enhanced Linux?

    I'm having the following issue: image module execs the
convert binary from the imagemagick package. Because this call
passes command line arguments, PHP execs bash to process the command.
The default SELinux policy does not allow httpd to execute bash, and
I don't particularly want to open exec permissions on bash to
anything run from httpd.

    Has anyone found a reasonable compromise for this situation?

puregin at puregin.org

