Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2666

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2008-2666
Last Modified 30 Oct 2012 10:58:13
Published 19 Jun 2008 09:41:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-2666

Summary

Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a subdirectory named http: and then placing ../ (dot dot slash) sequences in an http URL argument to the (1) chdir or (2) ftok function.

Vulnerable Systems

Application

  • Php 5.0

  • Php 5.0.0

  • Php 5.0.1

  • Php 5.0.2

  • Php 5.0.3

  • Php 5.0.4

  • Php 5.0.5

  • Php 5.1.0

  • Php 5.1.1

  • Php 5.1.2

  • Php 5.1.3

  • Php 5.1.4

  • Php 5.1.5

  • Php 5.1.6

  • Php 5.2.0

  • Php 5.2.1

  • Php 5.2.2

  • Php 5.2.3

  • Php 5.2.4

  • Php 5.2.5

  • Php 5.2.6


References

CERT - TA09-133A

XF - php-chdir-ftoc-security-bypass(43198)

VUPEN - ADV-2009-1297

SECTRACK - 1020328

BID - 29796

BUGTRAQ - 20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl

CONFIRM - http://wiki.rpath.com/Advisories:rPSA-2009-0035

CONFIRM - http://support.apple.com/kb/HT3549

SREASON - 3942

SREASONRES - 20080617 PHP 5.2.6 chdir(),ftok() (standard ext) safe_mode bypass

SECUNIA - 35650

SECUNIA - 35074

HP - SSRT090192

HP - SSRT090085

APPLE - APPLE-SA-2009-05-12

GENTOO - GLSA-200811-05

SECUNIA - 32746

HP - HPSBUX02465

HP - HPSBUX02431

Related Patches

Apple 2009-05-12 Mac OS X 10.5.7 Combo Update

Apple 2009-05-12 Mac OS X Server 10.5.7 Update

Apple 2009-05-12 Mac OS X 10.5.7 Update

Apple 2009-05-12 Mac OS X Server 10.5.7 Combo Update


Last Updated: 27 May 2016 10:55:04