Description
The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2010-1160 | The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function. |
Ubuntu USN |
USN-989-1 | PHP vulnerabilities |
References
History
Wed, 28 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Thu, 22 May 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T01:14:06.112Z
Reserved: 2010-03-26T00:00:00.000Z
Link: CVE-2010-1129
No data.
Status : Deferred
Published: 2010-03-26T20:30:00.907
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-1129
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN