Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-1017
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-1017

Description:
The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/24964

SREASON
  http://securityreason.com/securityalert/516

SAID
  Secunia Advisory: SA18694
  Secunia Advisory: SA21050
  Secunia Advisory: SA21546

OSVDB
  23535

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:122

CONFIRM
  http://www.php.net/release_5_1_5.php
  http://www.php.net/ChangeLog-5.php#5.1.5
  http://bugs.php.net/bug.php?id=37265

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/426339/100/0/threaded


Return to the previous page.