FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-2665

This CVE name corresponds to:

Entered Topic
2008-06-22 php -- input validation error in safe_mode

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-2665
Phase Assigned(20080610)

Description

Directory traversal vulnerability in the posix_access function in PHP 5.2.6 and earlier allows remote attackers to bypass safe_mode restrictions via a .. (dot dot) in an http URL, which results in the URL being canonicalized to a local filename after the safe_mode check has successfully run.

References

Source Reference
SREASONRES 20080617 PHP 5.2.6 posix_access() (posix ext) safe_mode bypass
BID 29797
SECTRACK 1020327
XF php-posixaccess-security-bypass(43196)