CVE-2006-3011
Summary
| CVE | CVE-2006-3011 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-26 21:05:00 UTC |
| Updated | 2017-07-20 01:31:00 UTC |
| Description | The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third argument, which disables safe mode. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Php |
Php |
1.0 |
All |
All |
All |
| Application |
Php |
Php |
2.0 |
All |
All |
All |
| Application |
Php |
Php |
2.0b10 |
All |
All |
All |
| Application |
Php |
Php |
3.0 |
All |
All |
All |
| Application |
Php |
Php |
3.0.1 |
All |
All |
All |
| Application |
Php |
Php |
3.0.10 |
All |
All |
All |
| Application |
Php |
Php |
3.0.11 |
All |
All |
All |
| Application |
Php |
Php |
3.0.12 |
All |
All |
All |
| Application |
Php |
Php |
3.0.13 |
All |
All |
All |
| Application |
Php |
Php |
3.0.14 |
All |
All |
All |
| Application |
Php |
Php |
3.0.15 |
All |
All |
All |
| Application |
Php |
Php |
3.0.16 |
All |
All |
All |
| Application |
Php |
Php |
3.0.17 |
All |
All |
All |
| Application |
Php |
Php |
3.0.18 |
All |
All |
All |
| Application |
Php |
Php |
3.0.2 |
All |
All |
All |
| Application |
Php |
Php |
3.0.3 |
All |
All |
All |
| Application |
Php |
Php |
3.0.4 |
All |
All |
All |
| Application |
Php |
Php |
3.0.5 |
All |
All |
All |
| Application |
Php |
Php |
3.0.6 |
All |
All |
All |
| Application |
Php |
Php |
3.0.7 |
All |
All |
All |
| Application |
Php |
Php |
3.0.8 |
All |
All |
All |
| Application |
Php |
Php |
3.0.9 |
All |
All |
All |
| Application |
Php |
Php |
4.0 |
beta1 |
All |
All |
| Application |
Php |
Php |
4.0 |
beta2 |
All |
All |
| Application |
Php |
Php |
4.0 |
beta3 |
All |
All |
| Application |
Php |
Php |
4.0 |
beta4 |
All |
All |
| Application |
Php |
Php |
4.0 |
beta_4_patch1 |
All |
All |
| Application |
Php |
Php |
4.0.0 |
All |
All |
All |
| Application |
Php |
Php |
4.0.1 |
All |
All |
All |
| Application |
Php |
Php |
4.0.2 |
All |
All |
All |
| Application |
Php |
Php |
4.0.3 |
All |
All |
All |
| Application |
Php |
Php |
4.0.4 |
All |
All |
All |
| Application |
Php |
Php |
4.0.5 |
All |
All |
All |
| Application |
Php |
Php |
4.0.6 |
All |
All |
All |
| Application |
Php |
Php |
4.0.7 |
All |
All |
All |
| Application |
Php |
Php |
4.1.0 |
All |
All |
All |
| Application |
Php |
Php |
4.1.1 |
All |
All |
All |
| Application |
Php |
Php |
4.1.2 |
All |
All |
All |
| Application |
Php |
Php |
4.2.0 |
All |
All |
All |
| Application |
Php |
Php |
4.2.1 |
All |
All |
All |
| Application |
Php |
Php |
4.2.2 |
All |
All |
All |
| Application |
Php |
Php |
4.2.3 |
All |
All |
All |
| Application |
Php |
Php |
4.3.0 |
All |
All |
All |
| Application |
Php |
Php |
4.3.1 |
All |
All |
All |
| Application |
Php |
Php |
4.3.10 |
All |
All |
All |
| Application |
Php |
Php |
4.3.11 |
All |
All |
All |
| Application |
Php |
Php |
4.3.2 |
All |
All |
All |
| Application |
Php |
Php |
4.3.3 |
All |
All |
All |
| Application |
Php |
Php |
4.3.4 |
All |
All |
All |
| Application |
Php |
Php |
4.3.5 |
All |
All |
All |
| Application |
Php |
Php |
4.3.6 |
All |
All |
All |
| Application |
Php |
Php |
4.3.7 |
All |
All |
All |
| Application |
Php |
Php |
4.3.8 |
All |
All |
All |
| Application |
Php |
Php |
4.3.9 |
All |
All |
All |
| Application |
Php |
Php |
4.4.0 |
All |
All |
All |
| Application |
Php |
Php |
4.4.1 |
All |
All |
All |
| Application |
Php |
Php |
4.4.2 |
All |
All |
All |
| Application |
Php |
Php |
5.0.0 |
All |
All |
All |
| Application |
Php |
Php |
5.0.0 |
beta1 |
All |
All |
| Application |
Php |
Php |
5.0.0 |
beta2 |
All |
All |
| Application |
Php |
Php |
5.0.0 |
beta3 |
All |
All |
| Application |
Php |
Php |
5.0.0 |
beta4 |
All |
All |
| Application |
Php |
Php |
5.0.0 |
rc1 |
All |
All |
| Application |
Php |
Php |
5.0.0 |
rc2 |
All |
All |
| Application |
Php |
Php |
5.0.0 |
rc3 |
All |
All |
| Application |
Php |
Php |
5.0.1 |
All |
All |
All |
| Application |
Php |
Php |
5.0.2 |
All |
All |
All |
| Application |
Php |
Php |
5.0.3 |
All |
All |
All |
| Application |
Php |
Php |
5.0.4 |
All |
All |
All |
| Application |
Php |
Php |
5.0.5 |
All |
All |
All |
| Application |
Php |
Php |
5.1.0 |
All |
All |
All |
| Application |
Php |
Php |
5.1.1 |
All |
All |
All |
| Application |
Php |
Php |
5.1.2 |
All |
All |
All |
| Application |
Php |
Php |
5.1.3 |
All |
All |
All |
| Application |
Php |
Php |
5.1.4 |
All |
All |
All |
| Application |
Php |
Php |
5.1.6 |
All |
All |
All |
| Application |
Php |
Php |
1.0 |
All |
All |
All |
| Application |
Php |
Php |
2.0 |
All |
All |
All |
| Application |
Php |
Php |
2.0b10 |
All |
All |
All |
| Application |
Php |
Php |
3.0 |
All |
All |
All |
| Application |
Php |
Php |
3.0.1 |
All |
All |
All |
| Application |
Php |
Php |
3.0.10 |
All |
All |
All |
| Application |
Php |
Php |
3.0.11 |
All |
All |
All |
| Application |
Php |
Php |
3.0.12 |
All |
All |
All |
| Application |
Php |
Php |
3.0.13 |
All |
All |
All |
| Application |
Php |
Php |
3.0.14 |
All |
All |
All |
| Application |
Php |
Php |
3.0.15 |
All |
All |
All |
| Application |
Php |
Php |
3.0.16 |
All |
All |
All |
| Application |
Php |
Php |
3.0.17 |
All |
All |
All |
| Application |
Php |
Php |
3.0.18 |
All |
All |
All |
| Application |
Php |
Php |
3.0.2 |
All |
All |
All |
| Application |
Php |
Php |
3.0.3 |
All |
All |
All |
| Application |
Php |
Php |
3.0.4 |
All |
All |
All |
| Application |
Php |
Php |
3.0.5 |
All |
All |
All |
| Application |
Php |
Php |
3.0.6 |
All |
All |
All |
| Application |
Php |
Php |
3.0.7 |
All |
All |
All |
| Application |
Php |
Php |
3.0.8 |
All |
All |
All |
| Application |
Php |
Php |
3.0.9 |
All |
All |
All |
| Application |
Php |
Php |
4.0 |
beta1 |
All |
All |
| Application |
Php |
Php |
4.0 |
beta2 |
All |
All |
| Application |
Php |
Php |
4.0 |
beta3 |
All |
All |
| Application |
Php |
Php |
4.0 |
beta4 |
All |
All |
| Application |
Php |
Php |
4.0 |
beta_4_patch1 |
All |
All |
| Application |
Php |
Php |
4.0.0 |
All |
All |
All |
| Application |
Php |
Php |
4.0.1 |
All |
All |
All |
| Application |
Php |
Php |
4.0.2 |
All |
All |
All |
| Application |
Php |
Php |
4.0.3 |
All |
All |
All |
| Application |
Php |
Php |
4.0.4 |
All |
All |
All |
| Application |
Php |
Php |
4.0.5 |
All |
All |
All |
| Application |
Php |
Php |
4.0.6 |
All |
All |
All |
| Application |
Php |
Php |
4.0.7 |
All |
All |
All |
| Application |
Php |
Php |
4.1.0 |
All |
All |
All |
| Application |
Php |
Php |
4.1.1 |
All |
All |
All |
| Application |
Php |
Php |
4.1.2 |
All |
All |
All |
| Application |
Php |
Php |
4.2.0 |
All |
All |
All |
| Application |
Php |
Php |
4.2.1 |
All |
All |
All |
| Application |
Php |
Php |
4.2.2 |
All |
All |
All |
| Application |
Php |
Php |
4.2.3 |
All |
All |
All |
| Application |
Php |
Php |
4.3.0 |
All |
All |
All |
| Application |
Php |
Php |
4.3.1 |
All |
All |
All |
| Application |
Php |
Php |
4.3.10 |
All |
All |
All |
| Application |
Php |
Php |
4.3.11 |
All |
All |
All |
| Application |
Php |
Php |
4.3.2 |
All |
All |
All |
| Application |
Php |
Php |
4.3.3 |
All |
All |
All |
| Application |
Php |
Php |
4.3.4 |
All |
All |
All |
| Application |
Php |
Php |
4.3.5 |
All |
All |
All |
| Application |
Php |
Php |
4.3.6 |
All |
All |
All |
| Application |
Php |
Php |
4.3.7 |
All |
All |
All |
| Application |
Php |
Php |
4.3.8 |
All |
All |
All |
| Application |
Php |
Php |
4.3.9 |
All |
All |
All |
| Application |
Php |
Php |
4.4.0 |
All |
All |
All |
| Application |
Php |
Php |
4.4.1 |
All |
All |
All |
| Application |
Php |
Php |
4.4.2 |
All |
All |
All |
| Application |
Php |
Php |
5.0.0 |
All |
All |
All |
| Application |
Php |
Php |
5.0.0 |
beta1 |
All |
All |
| Application |
Php |
Php |
5.0.0 |
beta2 |
All |
All |
| Application |
Php |
Php |
5.0.0 |
beta3 |
All |
All |
| Application |
Php |
Php |
5.0.0 |
beta4 |
All |
All |
| Application |
Php |
Php |
5.0.0 |
rc1 |
All |
All |
| Application |
Php |
Php |
5.0.0 |
rc2 |
All |
All |
| Application |
Php |
Php |
5.0.0 |
rc3 |
All |
All |
| Application |
Php |
Php |
5.0.1 |
All |
All |
All |
| Application |
Php |
Php |
5.0.2 |
All |
All |
All |
| Application |
Php |
Php |
5.0.3 |
All |
All |
All |
| Application |
Php |
Php |
5.0.4 |
All |
All |
All |
| Application |
Php |
Php |
5.0.5 |
All |
All |
All |
| Application |
Php |
Php |
5.1.0 |
All |
All |
All |
| Application |
Php |
Php |
5.1.1 |
All |
All |
All |
| Application |
Php |
Php |
5.1.2 |
All |
All |
All |
| Application |
Php |
Php |
5.1.3 |
All |
All |
All |
| Application |
Php |
Php |
5.1.4 |
All |
All |
All |
| Application |
Php |
Php |
5.1.6 |
All |
All |
All |
| Application |
Php |
Php |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| 26827 |
OSVDB |
www.osvdb.org |
|
| Advisories - Mandriva Linux |
MANDRIVA |
www.mandriva.com |
|
| PHP "error_log()" Safe Mode Bypass Weakness - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| SecurityReason - error_log() Safe Mode Bypass PHP 5.1.4 and 4.4.2 |
SREASON |
securityreason.com |
|
| Ubuntu update for PHP - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| PHP error_log() Function Lets Users Bypass Safe Mode File Access Restrictions - SecurityTracker |
SECTRACK |
securitytracker.com |
|
| cvs.php.net/viewvc.cgi/php-src/ext/standard/basic_functions.c |
CONFIRM |
cvs.php.net |
|
| usn/usn-320-1 - Ubuntu: Linux for human beings |
UBUNTU |
www.ubuntu.com |
|
| PHP: PHP 5.1.5 Release Announcement |
CONFIRM |
www.php.net |
|
| PHP Error_Log Safe_Mode Restriction-Bypass Vulnerability |
BID |
www.securityfocus.com |
|
| PHP Multiple Vulnerabilities - Advisories - Secunia |
SECUNIA |
secunia.com |
Patch, Vendor Advisory |
| cvs.php.net/viewvc.cgi/php-src/ext/standard/basic_functions.c |
CONFIRM |
cvs.php.net |
|
| Mandriva update for php - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH |
VUPEN |
www.vupen.com |
Vendor Advisory |
| IBM X-Force Exchange |
XF |
exchange.xforce.ibmcloud.com |
|
| SecurityReason - error_log() Safe Mode Bypass PHP 5.1.4 and 4.4.2 |
SREASONRES |
securityreason.com |
Exploit |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|
| Red Hat | 2006-09-20 | Mark J Cox | We do not consider these to be security issues. For more details see http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1 and http://www.php.net/security-note.php |
There are currently no legacy QID mappings associated with this CVE.