CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:N/I:P/A:N
AI Score
Confidence
High
EPSS
Percentile
80.3%
The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.
Vendor | Product | Version | CPE |
---|---|---|---|
php | php | 4.4.9 | cpe:/a:php:php:4.4.9::: |
php | php | 3.0.7 | cpe:/a:php:php:3.0.7::: |
php | php | 3.0.11 | cpe:/a:php:php:3.0.11::: |
php | php | 3.0.10 | cpe:/a:php:php:3.0.10::: |
php | php | 3.0.17 | cpe:/a:php:php:3.0.17::: |
php | php | 4.0.4 | cpe:/a:php:php:4.0.4::: |
php | php | 4.0.5 | cpe:/a:php:php:4.0.5::: |
php | php | 4.3.0 | cpe:/a:php:php:4.3.0::: |
php | php | 5.0.0 | cpe:/a:php:php:5.0.0:beta4:: |
php | php | 5.2.5 | cpe:/a:php:php:5.2.5::: |
lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
marc.info/?l=bugtraq&m=127680701405735&w=2
news.php.net/php.announce/79
secunia.com/advisories/37412
secunia.com/advisories/37821
secunia.com/advisories/40262
securityreason.com/securityalert/6601
support.apple.com/kb/HT4077
svn.php.net/viewvc/php/php-src/branches/PHP_5_2/ext/standard/file.c?view=log
svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/standard/file.c?view=log
svn.php.net/viewvc?view=revision&revision=288945
www.mandriva.com/security/advisories?name=MDVSA-2009:285
www.mandriva.com/security/advisories?name=MDVSA-2009:302
www.mandriva.com/security/advisories?name=MDVSA-2009:303
www.openwall.com/lists/oss-security/2009/11/20/2
www.openwall.com/lists/oss-security/2009/11/20/3
www.openwall.com/lists/oss-security/2009/11/20/5
www.php.net/ChangeLog-5.php
www.php.net/releases/5_2_12.php
www.php.net/releases/5_3_1.php
www.vupen.com/english/advisories/2009/3593
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7396