LWN.net Logo

php5: arbitrary file writes

Package(s):php5 CVE #(s):CVE-2012-0057
Created:January 31, 2012 Updated:April 13, 2012
Description: From the Debian advisory:

When applying a crafted XSLT transform, an attacker could write files to arbitrary places in the filesystem.

Alerts:
Debian DSA-2399-1 2012-01-31
Debian DSA-2399-2 2012-01-31
Ubuntu USN-1358-1 2012-02-09
SUSE SUSE-SU-2012:0411-1 2012-03-24
openSUSE openSUSE-SU-2012:0426-1 2012-03-29
SUSE SUSE-SU-2012:0472-1 2012-04-06
SUSE SUSE-SU-2012:0496-1 2012-04-12
Red Hat RHSA-2012:1045-01 2012-06-27
Red Hat RHSA-2012:1046-01 2012-06-27
Red Hat RHSA-2012:1047-01 2012-06-27
CentOS CESA-2012:1045 2012-06-27
CentOS CESA-2012:1047 2012-06-27
Oracle ELSA-2012-1045 2012-06-28
Oracle ELSA-2012-1047 2012-06-28
Oracle ELSA-2012-1046 2012-06-30
Scientific Linux SL-php-20120705 2012-07-05
Scientific Linux SL-php5-20120705 2012-07-05
Scientific Linux SL-php-20120709 2012-07-09
CentOS CESA-2012:1046 2012-07-10
Gentoo 201209-03 2012-09-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds