curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a x00 sequence, a different vulnerability than CVE-2006-2563.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php | Php | 5.2.4 (including) | 5.2.4 (including) |
Php | Php | 5.2.5 (including) | 5.2.5 (including) |
Php4 | Ubuntu | dapper | * |
Php4 | Ubuntu | edgy | * |
Php4 | Ubuntu | upstream | * |
Php5 | Ubuntu | devel | * |
Php5 | Ubuntu | edgy | * |
Php5 | Ubuntu | feisty | * |
Php5 | Ubuntu | gutsy | * |
Php5 | Ubuntu | hardy | * |
Php5 | Ubuntu | intrepid | * |
Php5 | Ubuntu | jaunty | * |
Php5 | Ubuntu | karmic | * |
Php5 | Ubuntu | upstream | * |