CVE-2007-0448

Publication date 24 May 2007

Last updated 17 July 2025


Ubuntu priority

Description

The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI.

Status

Package Ubuntu Release Status
php5 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected