CVE-2009-4024
Publication date 29 November 2009
Last updated 24 July 2024
Ubuntu priority
Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: this has also been reported as a shell metacharacter problem.
Status
Package | Ubuntu Release | Status |
---|---|---|
php-net-ping | 9.10 karmic |
Fixed 2.4.2-1+etch1build0.9.10.1
|
9.04 jaunty |
Fixed 2.4.2-1+etch1build0.9.04.1
|
|
8.10 intrepid |
Fixed 2.4.2-1+etch1build0.8.10.1
|
|
8.04 LTS hardy |
Fixed 2.4.2-1+etch1build0.8.04.1
|
|
6.06 LTS dapper | Not in release |