An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The linkinfo function on Windows doesn't implement the open_basedir check. This could be abused to find files on paths outside of the allowed directories.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T09:46:25.401Z

Reserved: 2018-08-07T00:00:00

Link: CVE-2018-15132

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-07T15:29:00.873

Modified: 2024-11-21T03:50:22.557

Link: CVE-2018-15132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.