CVE Database
/

CVE-2006-5178

Back to search

CVE-2006-5178

Published: Oct 6, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Race condition in the symlink function in PHP 5.1.6 and earlier allows local users to bypass the open_basedir restriction by using a combination of symlink, mkdir, and unlink functions to change the file path after the open_basedir check and before the file is opened by the underlying system, as demonstrated by symlinking a symlink into a subdirectory, to point to a parent directory via .. (dot dot) sequences, and then unlinking the resulting symlink.

VendorProductVersions

n/a

n/a

affected
n/a

References

OpenPKG-SA-2006.023
vendor-advisory
x_refsource_OPENPKG
TLSA-2006-38
vendor-advisory
x_refsource_TURBO
20326
vdb-entry
x_refsource_BID
1692
third-party-advisory
x_refsource_SREASON
22235
third-party-advisory
x_refsource_SECUNIA
ADV-2006-3901
vdb-entry
x_refsource_VUPEN
MDKSA-2006:185
vendor-advisory
x_refsource_MANDRIVA
1016977
vdb-entry
x_refsource_SECTRACK
22424
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now