Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2006-3011
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-3011

Description:
The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third argument, which disables safe mode.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/27414

UBUNTU
  http://www.ubuntu.com/usn/usn-320-1

ST
  1016377

SREASONRES
  http://securityreason.com/achievement_securityalert/41

SREASON
  http://securityreason.com/securityalert/1129

SAID
  Secunia Advisory: SA21125
  Secunia Advisory: SA21546
  Secunia Advisory: SA21050
  Secunia Advisory: SA20818

OSVDB
  26827

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:122

CONFIRM
  http://cvs.php.net/viewvc.cgi/php-src/ext/standard/basic_functions.c?diff_format=u&view=log&pathrev=PHP_4_4
  http://www.php.net/release_5_1_5.php
  http://cvs.php.net/viewvc.cgi/php-src/ext/standard/basic_functions.c?r1=1.543.2.51.2.9&r2=1.543.2.51.2.10&pathrev=PHP_4_4&diff_format=u

BID
  18645


Return to the previous page.