Back

LOW

CVE-2006-2660 tempnam() unique filename bypass

Published Jun 13, 2006

Description

Buffer consumption vulnerability in the tempnam function in PHP 5.1.4 and 4.x before 4.4.3 allows local users to bypass restrictions and create PHP files with fixed names in other directories via a pathname argument longer than MAXPATHLEN, which prevents a unique string from being appended to the filename.

Affected products

Remediation

Red Hat statement

This is not an issue that affects users of Red Hat Enterprise Linux. http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=196255

Weaknesses (0)

No CWE recorded.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 13, 2006
Updated Aug 7, 2024
Reserved May 30, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jul 11, 2006