CVE-2007-4850
Publication date 24 January 2008
Last updated 24 July 2024
Ubuntu priority
curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.
Status
Package | Ubuntu Release | Status |
---|---|---|
php4 | ||
php5 | ||
Notes
Patch details
Package | Patch details |
---|---|
php5 |
References
Related Ubuntu Security Notices (USN)
- USN-628-1
- PHP vulnerabilities
- 23 July 2008