Back

MEDIUM

CVE-2006-3011 multiple PHP safe mode bypasses (CVE-2006-4481, CVE-2006-2563)

Published Jun 26, 2006

Description

The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third argument, which disables safe mode.

Affected products

Remediation

Red Hat statement

We do not consider these to be security issues. For more details see http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1 and http://www.php.net/security-note.php

Metrics

Weaknesses (1)

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 26, 2006
Updated Aug 7, 2024
Reserved Jun 13, 2006
NVD
Status Modified
Modified Sep 23, 2026
Red Hat
Severity Low
Public date Jun 26, 2006