The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Php | — | Upgrade to PHP version 4.4.4Upgrade to PHP version 5.1.5 | Oct 1, 2012 | Mar 6, 2006 |
| Suse | — | Upgrade php8-dbaUpgrade php8-fpm-apacheUpgrade php8-intlUpgrade php8-ctypeUpgrade php8-enchantUpgrade php8-xslUpgrade php8Upgrade php8-mbstringUpgrade php8-zlibUpgrade php8-mysqlUpgrade php8-soapUpgrade php8-cliUpgrade php8-xmlwriterUpgrade php8-pdoUpgrade php8-odbcUpgrade php8-ffiUpgrade php8-tokenizerUpgrade php8-gdUpgrade php8-develUpgrade php8-calendarUpgrade php8-sysvsemUpgrade php8-opcacheUpgrade php8-sysvmsgUpgrade apache2-mod_php8Upgrade php8-gettextUpgrade php8-zipUpgrade php8-pgsqlUpgrade php8-bz2Upgrade php8-ftpUpgrade php8-domUpgrade php8-socketsUpgrade php8-snmpUpgrade php8-pharUpgrade php8-shmopUpgrade php8-tidyUpgrade php8-embedUpgrade php8-gmpUpgrade php8-exifUpgrade php8-fastcgiUpgrade php8-pcntlUpgrade php8-bcmathUpgrade php8-sodiumUpgrade php8-fpmUpgrade php8-fileinfoUpgrade php8-posixUpgrade php8-xmlreaderUpgrade php8-ldapUpgrade php8-iconvUpgrade php8-opensslUpgrade php8-sqliteUpgrade php8-sysvshmUpgrade php8-curlUpgrade php8-readline | Dec 12, 2013 | Jun 27, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub