The PHP package in Slackware 8.1, 9.0, and 9.1, when linked against a static library, includes /tmp in the search path, which allows local users to execute arbitrary code as the PHP user by inserting shared libraries into the appropriate path.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Slackware_linux | Slackware | 8.1 (including) | 8.1 (including) |
Slackware_linux | Slackware | 9.0 (including) | 9.0 (including) |
Slackware_linux | Slackware | 9.1 (including) | 9.1 (including) |