LOW
The cURL library (libcurl) in PHP 4.4.2 and 5.1.4 allows attackers to bypass safe mode and read files via a file:// request containing null characters
Published May 29, 2006
2.1
LOWCVSS 2.0
EPSS 0.41%
Description
The cURL library (libcurl) in PHP 4.4.2 and 5.1.4 allows attackers to bypass safe mode and read files via a file:// request containing null characters.
Affected products
Remediation
Red Hat statement
We do not consider these to be security issues. For more details see http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1 and http://www.php.net/security-note.php
Weaknesses (0)
No CWE recorded.
References (16)
- http://secunia.com/advisories/20337 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21050 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21847 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22039 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/achievement_securityalert/39 third-party-advisoryx_refsource_SREASONRES
- http://securityreason.com/securityalert/959 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1016175 vdb-entryx_refsource_SECTRACK
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:122 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006_22_sr.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2006_52_php.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/18116 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/2055 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-2563 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26764 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-2563
- https://www.cve.org/CVERecord?id=CVE-2006-2563
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 29, 2006
Updated Aug 7, 2024
Reserved May 23, 2006
Link CVE-2006-2563
CISA Vulnrichment
Updated n/a