FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-1635

This CVE name corresponds to:

Entered Topic
2013-03-18 php5 -- Multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-1635
Phase Assigned(20130207)

Description

ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote attackers to bypass intended access restrictions by triggering the creation of cached SOAP WSDL files in an arbitrary directory.

References

Source Reference
CONFIRM http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=702221
CONFIRM http://git.php.net/?p=php-src.git;a=blob;f=NEWS;h=36f6f9a4396d3034cc903a4271e7fdeccc5d3ea6;hb=refs/heads/PHP-5.4
CONFIRM http://git.php.net/?p=php-src.git;a=blob;f=NEWS;h=82afa3a040e639f3595121e45b850d5453906a00;hb=refs/heads/PHP-5.3
CONFIRM http://git.php.net/?p=php-src.git;a=commitdiff;h=702b436ef470cc02f8e2cc21f2fadeee42103c74
CONFIRM https://bugs.gentoo.org/show_bug.cgi?id=459904
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=918196
CONFIRM http://support.apple.com/kb/HT5880
CONFIRM https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0101
APPLE APPLE-SA-2013-09-12-1
DEBIAN DSA-2639
MANDRIVA MDVSA-2013:114
SUSE SUSE-SU-2013:1285
SUSE SUSE-SU-2013:1315