1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




PHP 5.2.13 Multiple Vulnerabilities

Report ID: SA201006418
Source: F-Secure
Date of Discovery: 09.03.2010
Criticality: Undefined
Affects:
PHP 5.2.12

Compromise From: Unknown
Compromise Type: Unknown

Summary

Vulnerabilities that involve safe_mode validation and safe_mode bypass have been reported in PHP 5.2.x branch.

Detailed Description

PHP has reported vulnerabilities that involve:

  • safe_mode validation inside tempnam() when the directory path does not end with a /)
  • open_basedir/safe_mode bypass in a session extension
  • LCG entropy

Solution

Update to PHP 5.2.13 or later versions

Original Reference

PHP 5.2.13 Released! (http://www.php.net/)