CVE-2007-4652

Priority
Negligible
Description
The session extension in PHP before 5.2.4 might allow local users to bypass
open_basedir restrictions via a session file that is a symlink.
References
Notes
kees> open_basedir not supported
Package
Source: php5 (LP Ubuntu Debian)
Upstream:released (5.2.4)
Ubuntu 8.04 LTS (Hardy Heron):not-affected (5.2.4-2ubuntu3)
More Information

Valid XHTML 1.0 Strict

Updated: 2012-06-01 15:22:48 UTC (commit 5347)