CVE-2007-3997

Publication date 4 September 2007

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

Description

The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE.

Read the notes from the security team

Status

Package Ubuntu Release Status
php4 7.10 gutsy Not in release
7.04 feisty Not in release
6.10 edgy Ignored
6.06 LTS dapper Ignored
php5 7.10 gutsy Ignored
7.04 feisty Ignored
6.10 edgy Ignored
6.06 LTS dapper Ignored

Notes


kees

safe_mode/open_basedir not supported