security flaw
Published Apr 10, 2006
2.6
LOWCVSS 2.0
EPSS 6.39%
Description
Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.
Affected products
No data.
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0.0
- 4.0.1
- 4.0.1
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.3
- 4.0.4
- 4.0.4
- 4.0.5
- 4.0.6
- 4.0.7
- 4.0.7
- 4.0.7
- 4.0.7
- 4.1.0
- 4.1.1
- 4.1.2
- 4.2
- 4.2.0
- 4.2.1
- 4.2.2
- 4.2.3
- 4.3.0
- 4.3.1
- 4.3.2
- 4.3.3
- 4.3.4
- 4.3.5
- 4.3.6
- 4.3.7
- 4.3.8
- 4.3.9
- 4.3.10
- 4.3.11
- 4.4.0
- 4.4.1
- 4.4.2
- 5.0
- 5.0
- 5.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.1
- 5.0.2
- 5.0.3
- 5.0.4
- 5.0.5
- 5.1.0
- 5.1.1
- 5.1.2
No data.
Red Hat Enterprise Linux 3
php-0:4.3.2-33.ent
Fixed · RHSA-2006:0568
Red Hat Enterprise Linux 4
php-0:4.3.9-3.15
Fixed · RHSA-2006:0568
Red Hat Enterprise Linux AS (Advanced Server) version 2.1
n/a
Fixed · RHSA-2006:0567
Red Hat Enterprise Linux ES version 2.1
n/a
Fixed · RHSA-2006:0567
Red Hat Enterprise Linux WS version 2.1
n/a
Fixed · RHSA-2006:0567
Red Hat Linux Advanced Workstation 2.1
n/a
Fixed · RHSA-2006:0567
Stronghold 4.0 for Red Hat Enterprise Linux AS (version 2.1)
n/a
Fixed · RHSA-2006:0549
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | php-0:4.3.2-33.ent | Fixed | RHSA-2006:0568 |
| Red Hat Enterprise Linux 4 | php-0:4.3.9-3.15 | Fixed | RHSA-2006:0568 |
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | n/a | Fixed | RHSA-2006:0567 |
| Red Hat Enterprise Linux ES version 2.1 | n/a | Fixed | RHSA-2006:0567 |
| Red Hat Enterprise Linux WS version 2.1 | n/a | Fixed | RHSA-2006:0567 |
| Red Hat Linux Advanced Workstation 2.1 | n/a | Fixed | RHSA-2006:0567 |
| Stronghold 4.0 for Red Hat Enterprise Linux AS (version 2.1) | n/a | Fixed | RHSA-2006:0549 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of OpenSSH as distributed with Red Hat Enterprise Linux 2.1, 3, or 4.
No CWE recorded.
References (31)
- ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U vendor-advisoryx_refsource_SGI
- http://rhn.redhat.com/errata/RHSA-2006-0549.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/19599 third-party-advisoryx_refsource_SECUNIAExploitPatchVendor Advisory
- http://secunia.com/advisories/19775 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19979 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21031 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21125 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21135 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21202 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21252 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21723 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22225 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/achievement_securityalert/36 third-party-advisoryx_refsource_SREASONRESExploitPatch
- http://securityreason.com/securityalert/677 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1015881 vdb-entryx_refsource_SECTRACK
- http://support.avaya.com/elmodocs2/security/ASA-2006-175.htm x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:074 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/05-05-2006.html vendor-advisoryx_refsource_SUSE
- http://www.redhat.com/support/errata/RHSA-2006-0567.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2006-0568.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/447866/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/17439 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-320-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2006/1290 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-1494 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1618037 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25705 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-683 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2006-1494
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10196 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-1494
Change history (0)
No recorded changes yet.