First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 207752
Alias:
Product:
Component:
Status: RESOLVED
Resolution: DUPLICATE of bug 209148
Assigned To: PHP Bugs <php-bugs@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Lars Hartmann <lars@chaotika.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 207752 depends on: Show dependency tree
Bug 207752 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-01-27 21:28 0000
curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5
allows context-dependent attackers to bypass safe_mode and open_basedir
restrictions and read arbitrary files via a file:// request containing a \x00
sequence.

------- Comment #1 From Christian Hoffmann 2008-01-27 21:32:21 0000 -------
Yep, saw that one in CVS already, will either provide a new patchset or
snapshot in the next days.
This is non-critical, I think. Gentoo Security rates safe_mode/open_basedir
issues with lowest priority (if at all), iirc.

Still, thanks to you and hanno /who messaged me about that today as well). :)

------- Comment #2 From Sune Kloppenborg Jeppesen 2008-01-28 18:29:21 0000 -------
PHP "safe mode" issues are traditionally not handled as security issues.

Reassigning to maintainer.

------- Comment #3 From Christian Hoffmann 2008-02-06 15:23:36 0000 -------
Marking as duplicate of bug 209148 which handles this and several other
security issues.

*** This bug has been marked as a duplicate of bug 209148 ***

First Last Prev Next    No search results available      Search page      Enter new bug