LWN.net Logo

Safemode vulnerability in PHP

Package(s):PHP CVE #(s):CAN-2001-1246
Created:August 20, 2002 Updated:October 9, 2002
Description: PHP versions 4.0.5 through 4.1.0 fail to properly cleanse a parameter to the mail() function, allowing arbitrary command execution by local and (possibly) remote attackers.
Alerts:
SuSE SuSE-SA:2002:036 2002-10-04
Debian DSA-168-1 2002-09-18
Mandrake MDKSA-2002:059 2002-09-10
Red Hat RHSA-2002:102-26 2002-08-19

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds