The cURL library (libcurl) in PHP 4.4.2 and 5.1.4 allows attackers to bypass safe mode and read files via a file:// request containing null characters.
Link | Tags |
---|---|
http://secunia.com/advisories/21847 | third party advisory |
http://secunia.com/advisories/20337 | third party advisory |
http://www.securityfocus.com/bid/18116 | vdb entry |
http://secunia.com/advisories/22039 | third party advisory |
http://secunia.com/advisories/21050 | third party advisory |
http://securityreason.com/securityalert/959 | third party advisory |
http://securityreason.com/achievement_securityalert/39 | third party advisory |
http://www.mandriva.com/security/advisories?name=MDKSA-2006:122 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26764 | vdb entry |
http://www.novell.com/linux/security/advisories/2006_22_sr.html | vendor advisory |
http://securitytracker.com/id?1016175 | vdb entry |
http://www.vupen.com/english/advisories/2006/2055 | vdb entry |
http://www.novell.com/linux/security/advisories/2006_52_php.html | vendor advisory |