CVE-2007-1460

Publication date 14 March 2007

Last updated 17 July 2025


Ubuntu priority

Description

The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 7.04 feisty Ignored
6.10 edgy Ignored
6.06 LTS dapper Ignored

Notes


kees

safe-mode bypass