PublicDate: 2006-09-12 16:07:00 UTC Candidate: CVE-2006-4625 References: https://ubuntu.com/security/notices/USN-362-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4625 Description: PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_php5: released (5.1.2-1ubuntu3.9) edgy_php5: released (5.1.6-1ubuntu2.6) feisty_php5: released (5.2.1-0ubuntu1.4) devel_php5: released (5.2.3-1ubuntu5) upstream_php5: needs-triage