An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The linkinfo function on Windows doesn't implement the open_basedir check. This could be abused to find files on paths outside of the allowed directories.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://php.net/ChangeLog-5.php | vendor advisory |
https://security.netapp.com/advisory/ntap-20181107-0003/ | third party advisory |
https://www.tenable.com/security/tns-2018-12 | third party advisory |
http://php.net/ChangeLog-7.php | vendor advisory |
https://github.com/php/php-src/commit/f151e048ed27f6f4eef729f3310d053ab5da71d4 | third party advisory patch |
https://bugs.php.net/bug.php?id=76459 | vendor advisory exploit |