PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a ";" in a session_save_path argument, followed by an allowed path, which causes a parsing inconsistency in which PHP validates the allowed path but sets session.save_path to the malicious path.
CVSS Details
- CVSS 3.1 Base Score: 7.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Php | — | Upgrade to PHP version 5.2.1 | Oct 1, 2012 | Dec 10, 2006 |
| Suse | — | Upgrade php4-exifUpgrade mod_php4-servletUpgrade php4-mysqlUpgrade php5-domUpgrade php4-sysvshmUpgrade php5-iconvUpgrade php4-develUpgrade php5-mhashUpgrade php5-sysvmsgUpgrade php5-pearUpgrade php4-pearUpgrade php5-soapUpgrade php5-ftpUpgrade php5-odbcUpgrade php5-exifUpgrade php5-mbstringUpgrade php5-curlUpgrade php5-xmlrpcUpgrade php4-sessionUpgrade php5-ldapUpgrade php5-imapUpgrade apache2-mod_php4Upgrade php4-wddxUpgrade php5-develUpgrade php5-pgsqlUpgrade mod_php4-coreUpgrade php5-bcmathUpgrade php5-dbaUpgrade php5-sysvshmUpgrade php5-mysqlUpgrade php5-wddxUpgrade php5-zipUpgrade php4-imapUpgrade apache-mod_php4Upgrade php4-unixODBCUpgrade php5-gdUpgrade php4-fastcgiUpgrade php5-fastcgiUpgrade php4-mhashUpgrade apache2-mod_php5Upgrade suse-release | Feb 17, 2015 | Dec 10, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub