LOW
CVE-2006-2660 tempnam() unique filename bypass
Published Jun 13, 2006
2.1
LOWCVSS 2.0
EPSS 0.35%
Description
Buffer consumption vulnerability in the tempnam function in PHP 5.1.4 and 4.x before 4.4.3 allows local users to bypass restrictions and create PHP files with fixed names in other directories via a pathname argument longer than MAXPATHLEN, which prevents a unique string from being appended to the filename.
Affected products
No data.
OR
- 4.0.0
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.4
- 4.0.5
- 4.1.0
- 4.1.1
- 4.1.2
- 4.2.0
- 4.2.1
- 4.2.2
- 4.2.3
- 4.3.0
- 4.3.1
- 4.3.2
- 4.3.3
- 4.3.4
- 4.3.5
- 4.3.6
- 4.3.7
- 4.3.8
- 4.3.9
- 4.3.10
- 4.3.11
- 4.4.0
- 4.4.1
- 4.4.2
- 4.4.3
- 5.1.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This is not an issue that affects users of Red Hat Enterprise Linux. http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=196255
Weaknesses (0)
No CWE recorded.
References (13)
- http://archives.neohapsis.com/archives/fulldisclosure/2006-06/0209.html mailing-listx_refsource_FULLDISC
- http://cvs.php.net/viewcvs.cgi/php-src/NEWS?view=markup&rev=1.1247.2.920.2.134 x_refsource_CONFIRM
- http://secunia.com/advisories/21125 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/1069 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1016271 vdb-entryx_refsource_SECTRACK
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:122 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/archive/1/436785/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.ubuntu.com/usn/usn-320-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2006-2660 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=195539 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27049 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-2660
- https://www.cve.org/CVERecord?id=CVE-2006-2660
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 13, 2006
Updated Aug 7, 2024
Reserved May 30, 2006
Link CVE-2006-2660
CISA Vulnrichment
Updated n/a