CVE-2007-4652
Priority
Negligible
Description
The session extension in PHP before 5.2.4 might allow local users to bypass
open_basedir restrictions via a session file that is a symlink.
References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4652
Notes
kees> open_basedir not supported
Package
Source:
php5
(
LP
Ubuntu
Debian
)
Upstream:
released
(5.2.4)
Ubuntu 8.04 LTS (Hardy Heron)
:
not-affected
(5.2.4-2ubuntu3)
More Information
Mitre
NVD
Launchpad
Debian
Updated
: 2012-06-01 15:22:48 UTC (commit
5347
)