The cURL library (libcurl) in PHP 4.4.2 and 5.1.4 allows attackers to bypass safe mode and read files via a file:// request containing null characters.
CVSS Details
- CVSS 3.1 Base Score: 4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Php | — | Upgrade to PHP version 5.1.5Upgrade to PHP version 4.4.3 | Oct 1, 2012 | May 29, 2006 |
| Suse | — | Upgrade php5-suhosinUpgrade php4-mbstringUpgrade php4-exifUpgrade php4-sysvshmUpgrade mod_php4-coreUpgrade php4-develUpgrade php4-fastcgiUpgrade php4-recodeUpgrade mod_php4-servletUpgrade php4-sessionUpgrade apache-mod_php4Upgrade php4-wddxUpgrade php4-mysqlUpgrade php4-curlUpgrade php4-pearUpgrade php4-gdUpgrade php4-imapUpgrade php4-pgsqlUpgrade apache2-mod_php4 | Feb 17, 2015 | May 29, 2006 |
| Ubuntu | — | Upgrade php4-cgiUpgrade php4-cliUpgrade php5-cliUpgrade php5-curlUpgrade libapache2-mod-php4Upgrade libapache2-mod-php5Upgrade php5-cgi | Nov 8, 2024 | May 29, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub