CVE-2007-4850
Publication date 24 January 2008
Last updated 24 July 2024
Ubuntu priority
Description
curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| php4 | ||
| php5 | ||
Notes
Patch details
| Package | Patch details |
|---|---|
| php5 |
References
Related Ubuntu Security Notices (USN)
- USN-628-1
- PHP vulnerabilities
- 23 July 2008