Skip to navigation
Skip to content
Skip to secondary-content
F-Secure
Tools
Choose Location:
Corporation - English
Corporation - Finnish
Labs
------------
Australia
Belgium - Dutch
Belgium - French
Brazil
Denmark
Estonia
Finland
France
Germany
Global
Greece
Hong Kong
India
Italy
Japan
Malaysia
Netherlands
New Zealand
Poland
Russia
Slovenia
Sweden
UK
USA
Search
Go
Navigation
Labs
News & Info
Security Threats
Virus Encyclopedia
Submit Samples
Beta Programs
Subnavigation
Virus & Threat Descriptions
Vulnerability Reports
Mobile Security Threats
Threat Removal
Free Removal Tools
Labs
Latest Threats
Submit Samples
Removal Tools
Virus Encyclopedia
Where You Are
Labs
Security Threats
Vulnerability Reports
SA201006418
PHP 5.2.13 Multiple Vulnerabilities
Report ID:
SA201006418
Source:
F-Secure
Date of Discovery:
09.03.2010
Criticality:
Undefined
Affects:
PHP 5.2.12
Compromise From:
Unknown
Compromise Type:
Unknown
Summary
Vulnerabilities that involve safe_mode validation and safe_mode bypass have been reported in PHP 5.2.x branch.
Detailed Description
PHP has reported vulnerabilities that involve:
• safe_mode validation inside tempnam() when the directory path does not end with a /)
• open_basedir/safe_mode bypass in a session extension
• LCG entropy
Solution
Update to PHP 5.2.13 or later versions
Original Reference
PHP 5.2.13 Released! (
http://www.php.net/
)