|
|
Info |
Last Modified |
| 14 days ago |
|
|
|
|
Description |
PHP cURL (aka libcurl) could allow context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality
Solution:
Upgrade
Disclosure:
Vendor Verified
OSVDB:
Context Dependent
|
|
Solution |
Upgrade to PHP 5.2.6 or higher, as it has been reported to fix this vulnerability. In addition, fixes are available in the php.net SVN repository.
|
|
Products |
|
libcURL
 |
5.2.4 |
5.2.5 |
|
|
|
|
|
|
Credit |
- Maksymilian Arciemowicz - max
jestsuper.pl - securityreason.com
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|