Buffer consumption vulnerability in the tempnam function in PHP 5.1.4 and 4.x before 4.4.3 allows local users to bypass restrictions and create PHP files with fixed names in other directories via a pathname argument longer than MAXPATHLEN, which prevents a unique string from being appended to the filename.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Php | — | Upgrade to PHP version 5.1.5Upgrade to PHP version 4.4.3 | Oct 1, 2012 | Jun 13, 2006 |
| Suse | — | Upgrade php5-suhosin | Dec 12, 2013 | Jun 13, 2006 |
| Ubuntu | — | Upgrade php5-cgiUpgrade php5-curlUpgrade php4-cliUpgrade php5-cliUpgrade libapache2-mod-php5Upgrade libapache2-mod-php4Upgrade php4-cgi | Nov 8, 2024 | Jun 13, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub