LWN.net Logo

php: restriction bypass

Package(s):php CVE #(s):CVE-2006-4625 CVE-2006-5178
Created:October 18, 2006 Updated:October 18, 2006
Description: The ini_restore() function in PHP versions through 4.4.4 and 5.1.6 can be used to bypass safe_mode and init_basedir restrictions.

Also: race condition in PHP's handling of the symlink() function can enable hostile code to bypass open_basedir restrictions.

Alerts:
Trustix TSLSA-2006-0057 2006-10-18
Mandriva MDKSA-2006:185 2006-10-17

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds