CVE-2008-5624
Publication date 17 December 2008
Last updated 24 July 2024
Ubuntu priority
PHP 5 before 5.2.7 does not properly initialize the page_uid and page_gid global variables for use by the SAPI php_getuid function, which allows context-dependent attackers to bypass safe_mode restrictions via variable settings that are intended to be restricted to root, as demonstrated by a setting of /etc for the error_log variable.
Status
Package | Ubuntu Release | Status |
---|---|---|
php4 | ||
php5 | ||
Notes
mdeslaur
the second upstream patch is for apache 1.x sapi apache 1.x is still in Dapper, so we better include it
Patch details
References
Related Ubuntu Security Notices (USN)
- USN-720-1
- PHP vulnerabilities
- 12 February 2009