Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-1614
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-1614

Description:
suPHP before 0.6.3 allows local users to gain privileges via (1) a race condition that involves multiple symlink changes to point a file owned by a different user, or (2) a symlink to the directory of a different user, which is used to determine privileges.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/41582

SAID
  Secunia Advisory: SA29648
  Secunia Advisory: SA29615
  Secunia Advisory: SA29872

MLIST
  http://lists.marsching.biz/pipermail/suphp/2008-March/001750.html

MISC

FEDORA

DEBIAN
  http://www.debian.org/security/2008/dsa-1550

BID
  28568


Return to the previous page.