CVE-2007-4889

Publication date 14 September 2007

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

Description

The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (2) INTO DUMPFILE, and (3) INTO OUTFILE functions, a different issue than CVE-2007-3997.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 7.10 gutsy Ignored
7.04 feisty Ignored
6.10 edgy Ignored
6.06 LTS dapper Ignored

Notes


kees

basedir and safemode not supported