PHP before 5.2.5 allows local users to bypass protection mechanisms configured through php_admin_value or php_admin_flag in httpd.conf by using ini_set to modify arbitrary configuration variables, a different issue than CVE-2006-4625.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.php.net/ChangeLog-5.php#5.2.5 | |
https://issues.rpath.com/browse/RPL-1943 | |
http://securitytracker.com/id?1018934 | vdb entry |
http://secunia.com/advisories/30040 | third party advisory |
http://www.php.net/releases/5_2_5.php | |
http://secunia.com/advisories/27659 | third party advisory |
http://www.securityfocus.com/archive/1/491693/100/0/threaded | vendor advisory |
http://secunia.com/advisories/27648 | third party advisory patch vendor advisory |
http://bugs.php.net/bug.php?id=41561 | |
http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0242 |