CVE-2009-1272

Publication date 8 April 2009

Last updated 24 July 2024


Ubuntu priority

Description

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
6.06 LTS dapper
Not affected

Notes


mdeslaur

this is caused by an incomplete fix for CVE-2008-5658. our patch was complete, so we're not affected

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
php5