CVE-2008-2665

Publication date 20 June 2008

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

Description

Directory traversal vulnerability in the posix_access function in PHP 5.2.6 and earlier allows remote attackers to bypass safe_mode restrictions via a .. (dot dot) in an http URL, which results in the URL being canonicalized to a local filename after the safe_mode check has successfully run.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 8.04 LTS hardy Ignored end of life, was needed
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.06 LTS dapper Ignored end of life, was needed

Notes


kees

safe mode not supported