CVE-2012-1171

Publication date 15 February 2014

Last updated 24 July 2024


Ubuntu priority

Description

The libxml RSHUTDOWN function in PHP 5.x allows remote attackers to bypass the open_basedir protection mechanism and read arbitrary files via vectors involving a stream_close method call during use of a custom stream wrapper.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 11.10 oneiric Ignored
11.04 natty Ignored
10.04 LTS lucid Ignored
8.04 LTS hardy Ignored

Notes


jdstrand

safe_mode - open_basedir bypass, ignoring