CVE-2008-2666

Publication date 20 June 2008

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

Description

Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a subdirectory named http: and then placing ../ (dot dot slash) sequences in an http URL argument to the (1) chdir or (2) ftok function.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 8.04 LTS hardy Ignored end of life, was needed
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.06 LTS dapper Ignored end of life, was needed

Notes


kees

safe_mode not supported