FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-3558

This CVE name corresponds to:

Entered Topic
2009-12-17 php -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-3558
Phase Assigned(20091005)

Description

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file.

References

Source Reference
MLIST [oss-security] 20091120 CVE request: php 5.3.1 update
MLIST [oss-security] 20091120 Re: CVE request: php 5.3.1 update
MLIST [oss-security] 20091120 Re: CVE request: php 5.3.1 update
MLIST [php-announce] 20091119 5.3.1 Release announcement
CONFIRM http://svn.php.net/viewvc/php/php-src/branches/PHP_5_2/ext/posix/posix.c?view=log
CONFIRM http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/posix/posix.c?view=log
CONFIRM http://svn.php.net/viewvc?view=revision&revision=288943
CONFIRM http://www.php.net/ChangeLog-5.php
CONFIRM http://www.php.net/releases/5_3_1.php
CONFIRM http://www.php.net/releases/5_2_12.php
CONFIRM http://support.apple.com/kb/HT4077
APPLE APPLE-SA-2010-03-29-1
MANDRIVA MDVSA-2009:302
MANDRIVA MDVSA-2009:285
MANDRIVA MDVSA-2009:303
SECUNIA 37412
SECUNIA 37821
SREASON 6600
VUPEN ADV-2009-3593