CVE-2013-1635
Summary
| CVE | CVE-2013-1635 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-03-06 13:10:27 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote attackers to bypass intended access restrictions by triggering the creation of cached SOAP WSDL files in an arbitrary directory. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Php | Php | 1.0 | All | All | All |
| Application | Php | Php | 2.0 | All | All | All |
| Application | Php | Php | 2.0b10 | All | All | All |
| Application | Php | Php | 3.0 | All | All | All |
| Application | Php | Php | 3.0.1 | All | All | All |
| Application | Php | Php | 3.0.10 | All | All | All |
| Application | Php | Php | 3.0.11 | All | All | All |
| Application | Php | Php | 3.0.12 | All | All | All |
| Application | Php | Php | 3.0.13 | All | All | All |
| Application | Php | Php | 3.0.14 | All | All | All |
| Application | Php | Php | 3.0.15 | All | All | All |
| Application | Php | Php | 3.0.16 | All | All | All |
| Application | Php | Php | 3.0.17 | All | All | All |
| Application | Php | Php | 3.0.18 | All | All | All |
| Application | Php | Php | 3.0.2 | All | All | All |
| Application | Php | Php | 3.0.3 | All | All | All |
| Application | Php | Php | 3.0.4 | All | All | All |
| Application | Php | Php | 3.0.5 | All | All | All |
| Application | Php | Php | 3.0.6 | All | All | All |
| Application | Php | Php | 3.0.7 | All | All | All |
| Application | Php | Php | 3.0.8 | All | All | All |
| Application | Php | Php | 3.0.9 | All | All | All |
| Application | Php | Php | 4.0 | beta1 | All | All |
| Application | Php | Php | 4.0 | beta2 | All | All |
| Application | Php | Php | 4.0 | beta3 | All | All |
| Application | Php | Php | 4.0 | beta4 | All | All |
| Application | Php | Php | 4.0 | beta_4_patch1 | All | All |
| Application | Php | Php | 4.0.0 | All | All | All |
| Application | Php | Php | 4.0.1 | All | All | All |
| Application | Php | Php | 4.0.2 | All | All | All |
| Application | Php | Php | 4.0.3 | All | All | All |
| Application | Php | Php | 4.0.4 | All | All | All |
| Application | Php | Php | 4.0.5 | All | All | All |
| Application | Php | Php | 4.0.6 | All | All | All |
| Application | Php | Php | 4.0.7 | All | All | All |
| Application | Php | Php | 4.1.0 | All | All | All |
| Application | Php | Php | 4.1.1 | All | All | All |
| Application | Php | Php | 4.1.2 | All | All | All |
| Application | Php | Php | 4.2.0 | All | All | All |
| Application | Php | Php | 4.2.1 | All | All | All |
| Application | Php | Php | 4.2.2 | All | All | All |
| Application | Php | Php | 4.2.3 | All | All | All |
| Application | Php | Php | 4.3.0 | All | All | All |
| Application | Php | Php | 4.3.1 | All | All | All |
| Application | Php | Php | 4.3.10 | All | All | All |
| Application | Php | Php | 4.3.11 | All | All | All |
| Application | Php | Php | 4.3.2 | All | All | All |
| Application | Php | Php | 4.3.3 | All | All | All |
| Application | Php | Php | 4.3.4 | All | All | All |
| Application | Php | Php | 4.3.5 | All | All | All |
| Application | Php | Php | 4.3.6 | All | All | All |
| Application | Php | Php | 4.3.7 | All | All | All |
| Application | Php | Php | 4.3.8 | All | All | All |
| Application | Php | Php | 4.3.9 | All | All | All |
| Application | Php | Php | 4.4.0 | All | All | All |
| Application | Php | Php | 4.4.1 | All | All | All |
| Application | Php | Php | 4.4.2 | All | All | All |
| Application | Php | Php | 4.4.3 | All | All | All |
| Application | Php | Php | 4.4.4 | All | All | All |
| Application | Php | Php | 4.4.5 | All | All | All |
| Application | Php | Php | 4.4.6 | All | All | All |
| Application | Php | Php | 4.4.7 | All | All | All |
| Application | Php | Php | 4.4.8 | All | All | All |
| Application | Php | Php | 4.4.9 | All | All | All |
| Application | Php | Php | 5.0.0 | All | All | All |
| Application | Php | Php | 5.0.0 | beta1 | All | All |
| Application | Php | Php | 5.0.0 | beta2 | All | All |
| Application | Php | Php | 5.0.0 | beta3 | All | All |
| Application | Php | Php | 5.0.0 | beta4 | All | All |
| Application | Php | Php | 5.0.0 | rc1 | All | All |
| Application | Php | Php | 5.0.0 | rc2 | All | All |
| Application | Php | Php | 5.0.0 | rc3 | All | All |
| Application | Php | Php | 5.0.1 | All | All | All |
| Application | Php | Php | 5.0.2 | All | All | All |
| Application | Php | Php | 5.0.3 | All | All | All |
| Application | Php | Php | 5.0.4 | All | All | All |
| Application | Php | Php | 5.0.5 | All | All | All |
| Application | Php | Php | 5.1.0 | All | All | All |
| Application | Php | Php | 5.1.1 | All | All | All |
| Application | Php | Php | 5.1.2 | All | All | All |
| Application | Php | Php | 5.1.3 | All | All | All |
| Application | Php | Php | 5.1.4 | All | All | All |
| Application | Php | Php | 5.1.5 | All | All | All |
| Application | Php | Php | 5.1.6 | All | All | All |
| Application | Php | Php | 5.2.0 | All | All | All |
| Application | Php | Php | 5.2.1 | All | All | All |
| Application | Php | Php | 5.2.10 | All | All | All |
| Application | Php | Php | 5.2.11 | All | All | All |
| Application | Php | Php | 5.2.12 | All | All | All |
| Application | Php | Php | 5.2.13 | All | All | All |
| Application | Php | Php | 5.2.14 | All | All | All |
| Application | Php | Php | 5.2.15 | All | All | All |
| Application | Php | Php | 5.2.16 | All | All | All |
| Application | Php | Php | 5.2.17 | All | All | All |
| Application | Php | Php | 5.2.2 | All | All | All |
| Application | Php | Php | 5.2.3 | All | All | All |
| Application | Php | Php | 5.2.4 | All | All | All |
| Application | Php | Php | 5.2.5 | All | All | All |
| Application | Php | Php | 5.2.6 | All | All | All |
| Application | Php | Php | 5.2.7 | All | All | All |
| Application | Php | Php | 5.2.8 | All | All | All |
| Application | Php | Php | 5.2.9 | All | All | All |
| Application | Php | Php | 5.3.0 | All | All | All |
| Application | Php | Php | 5.3.1 | All | All | All |
| Application | Php | Php | 5.3.10 | All | All | All |
| Application | Php | Php | 5.3.11 | All | All | All |
| Application | Php | Php | 5.3.12 | All | All | All |
| Application | Php | Php | 5.3.13 | All | All | All |
| Application | Php | Php | 5.3.14 | All | All | All |
| Application | Php | Php | 5.3.15 | All | All | All |
| Application | Php | Php | 5.3.16 | All | All | All |
| Application | Php | Php | 5.3.17 | All | All | All |
| Application | Php | Php | 5.3.18 | All | All | All |
| Application | Php | Php | 5.3.19 | All | All | All |
| Application | Php | Php | 5.3.2 | All | All | All |
| Application | Php | Php | 5.3.20 | All | All | All |
| Application | Php | Php | 5.3.3 | All | All | All |
| Application | Php | Php | 5.3.4 | All | All | All |
| Application | Php | Php | 5.3.5 | All | All | All |
| Application | Php | Php | 5.3.6 | All | All | All |
| Application | Php | Php | 5.3.7 | All | All | All |
| Application | Php | Php | 5.3.8 | All | All | All |
| Application | Php | Php | 5.3.9 | All | All | All |
| Application | Php | Php | 5.4.0 | All | All | All |
| Application | Php | Php | 5.4.1 | All | All | All |
| Application | Php | Php | 5.4.10 | All | All | All |
| Application | Php | Php | 5.4.11 | All | All | All |
| Application | Php | Php | 5.4.12 | All | All | All |
| Application | Php | Php | 5.4.2 | All | All | All |
| Application | Php | Php | 5.4.3 | All | All | All |
| Application | Php | Php | 5.4.4 | All | All | All |
| Application | Php | Php | 5.4.5 | All | All | All |
| Application | Php | Php | 5.4.6 | All | All | All |
| Application | Php | Php | 5.4.7 | All | All | All |
| Application | Php | Php | 5.4.8 | All | All | All |
| Application | Php | Php | 5.4.9 | All | All | All |
| Application | Php | Php | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-2639-1 php5 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Support/Advisories/MGASA-2013-0101 - Mageia wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.mageia.org | |
| [security-announce] SUSE-SU-2013:1315-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| APPLE-SA-2013-09-12-1 OS X Mountain Lion v10.8.5 and Security Update 2013-004 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| About the security content of OS X Mountain Lion v10.8.5 and Security Update 2013-004 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Support / Security / Advisories / / MDVSA-2013:114 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| 459904 – (CVE-2013-1635) <dev-lang/php-{5.3.23,5.4.13}: Multiple vulnerabilities in the SOAP extensions has been discovered and corrected (CVE-2013-{1635,1643}) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| Bug 918196 – CVE-2013-1635 php, php53: Arbitrary locations file write due absent validation of soap.wsdl_cache_dir configuration directive value | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| #702221 - php5: CVE-2013-1635 CVE-2013-1643 - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| 208.43.231.11 Git - php-src.git/blob - NEWS | af854a3a-2127-422b-91ae-364da2661108 | git.php.net | |
| [security-announce] SUSE-SU-2013:1285-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| 208.43.231.11 Git - php-src.git/commitdiff | af854a3a-2127-422b-91ae-364da2661108 | git.php.net | |
| 208.43.231.11 Git - php-src.git/blob - NEWS | af854a3a-2127-422b-91ae-364da2661108 | git.php.net | |
| 208.43.231.11 Git - php-src.git/blob - NEWS | MITRE | git.php.net | |
| 208.43.231.11 Git - php-src.git/blob - NEWS | MITRE | git.php.net | |
| 208.43.231.11 Git - php-src.git/commitdiff | MITRE | git.php.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.