6.2

CVE-2006-5178

Exploit
Race condition in the symlink function in PHP 5.1.6 and earlier allows local users to bypass the open_basedir restriction by using a combination of symlink, mkdir, and unlink functions to change the file path after the open_basedir check and before the file is opened by the underlying system, as demonstrated by symlinking a symlink into a subdirectory, to point to a parent directory via .. (dot dot) sequences, and then unlinking the resulting symlink.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version <= 5.1.6
Php ≫ Php Version 4.0
Php ≫ Php Version 4.0.1
Php ≫ Php Version 4.0.1 Update patch1
Php ≫ Php Version 4.0.1 Update patch2
Php ≫ Php Version 4.0.2
Php ≫ Php Version 4.0.3 Update patch1
Php ≫ Php Version 4.0.4
Php ≫ Php Version 4.0.5
Php ≫ Php Version 4.0.6
Php ≫ Php Version 4.0.7
Php ≫ Php Version 4.0.7 Update rc1
Php ≫ Php Version 4.0.7 Update rc2
Php ≫ Php Version 4.0.7 Update rc3
Php ≫ Php Version 4.1.0
Php ≫ Php Version 4.1.1
Php ≫ Php Version 4.1.2
Php ≫ Php Version 4.2 Edition dev
Php ≫ Php Version 4.2.0
Php ≫ Php Version 4.2.1
Php ≫ Php Version 4.2.2
Php ≫ Php Version 4.2.3
Php ≫ Php Version 4.3.0
Php ≫ Php Version 4.3.1
Php ≫ Php Version 4.3.2
Php ≫ Php Version 4.3.3
Php ≫ Php Version 4.3.4
Php ≫ Php Version 4.3.5
Php ≫ Php Version 4.3.6
Php ≫ Php Version 4.3.7
Php ≫ Php Version 4.3.8
Php ≫ Php Version 4.3.9
Php ≫ Php Version 4.3.10
Php ≫ Php Version 4.3.11
Php ≫ Php Version 4.4.0
Php ≫ Php Version 4.4.1
Php ≫ Php Version 4.4.2
Php ≫ Php Version 4.4.3
Php ≫ Php Version 4.4.4
Php ≫ Php Version 5.0 Update rc1
Php ≫ Php Version 5.0 Update rc2
Php ≫ Php Version 5.0 Update rc3
Php ≫ Php Version 5.0.0
Php ≫ Php Version 5.0.1
Php ≫ Php Version 5.0.2
Php ≫ Php Version 5.0.3
Php ≫ Php Version 5.0.4
Php ≫ Php Version 5.0.5
Php ≫ Php Version 5.1.0
Php ≫ Php Version 5.1.1
Php ≫ Php Version 5.1.2
Php ≫ Php Version 5.1.3
Php ≫ Php Version 5.1.4
Php ≫ Php Version 5.1.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.68% 0.482
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.2 1.9 10
AV:L/AC:H/Au:N/C:C/I:C/A:C
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

http://www.turbolinux.com/security/2006/TLSA-2006-38.txt
http://secunia.com/advisories/22424
http://www.mandriva.com/security/advisories?name=MDKSA-2006:185
http://www.securityfocus.com/archive/1/448953/100/0/threaded
http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/049850.html
Exploit
http://secunia.com/advisories/22235
Vendor Advisory
Exploit
http://securityreason.com/securityalert/1692
http://securitytracker.com/id?1016977
Exploit
http://www.hardened-php.net/advisory_082006.132.html
Vendor Advisory
Exploit
http://www.neosecurityteam.net/index.php?action=advisories&id=26
http://www.securityfocus.com/archive/1/447649/100/0/threaded
http://www.securityfocus.com/archive/1/448020/100/0/threaded
http://www.securityfocus.com/bid/20326
Exploit
http://www.vupen.com/english/advisories/2006/3901
https://exchange.xforce.ibmcloud.com/vulnerabilities/29340