Back

MEDIUM

php: posix_access() (posix ext) safe_mode bypass

Published Jun 20, 2008

Description

Directory traversal vulnerability in the posix_access function in PHP 5.2.6 and earlier allows remote attackers to bypass safe_mode restrictions via a .. (dot dot) in an http URL, which results in the URL being canonicalized to a local filename after the safe_mode check has successfully run.

Affected products

Remediation

Red Hat statement

We do not consider these to be security issues. For more details see https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1 and https://www.php.net/security-note.php

Metrics

Weaknesses (1)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 20, 2008
Updated Aug 7, 2024
Reserved Jun 10, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jun 18, 2008