FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-0905

This CVE name corresponds to:

Entered Topic
2007-02-17 php -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-0905
Phase Assigned(20070213)

Description

PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension. NOTE: it is possible that this issue is a duplicate of CVE-2006-6383.

References

Source Reference
CONFIRM http://www.php.net/ChangeLog-5.php#5.2.1
CONFIRM http://www.php.net/releases/5_2_1.php
OPENPKG OpenPKG-SA-2007.010
TRUSTIX 2007-0009
BID 22496
VUPEN ADV-2007-0546
OSVDB 32768
SECUNIA 24089
SECUNIA 24419