Back

HIGH

php: incorrect php_value order for Apache configuration

Published Dec 17, 2008

Description

PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, which allows context-dependent attackers to write to arbitrary files by placing a "php_value error_log" entry in a .htaccess file.

Affected products

Remediation

Red Hat statement

We do not consider this to be a security issue. For more details see https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1 and https://www.php.net/security-note.php

Metrics

Weaknesses (1)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 17, 2008
Updated Aug 7, 2024
Reserved Dec 17, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Dec 4, 2008