LWN.net Logo

php: symlink attack

Package(s):php CVE #(s):CVE-2011-0441
Created:April 8, 2011 Updated:May 5, 2011
Description: From the Mandriva advisory:

It was discovered that the /etc/cron.d/php cron job for php-session allows local users to delete arbitrary files via a symlink attack on a directory under /var/lib/php.

Alerts:
Ubuntu USN-1126-2 2011-05-05
Ubuntu USN-1126-1 2011-04-29
Mandriva MDVSA-2011:069 2011-04-08
Ubuntu USN-1358-1 2012-02-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds