PHP BZip2/Zip Wrappers Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
BID:22954
Info
PHP BZip2/Zip Wrappers Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
| Bugtraq ID: | 22954 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-1460 CVE-2007-1461 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 13 2007 12:00AM |
| Updated: | Jul 06 2016 02:39PM |
| Credit: | Stefan Esser discovered these issues. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 10 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux 9.3 x86-64 S.u.S.E. Linux 9.3 x86 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc PHP PHP 5.2.1 PHP PHP 5.1.6 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 -RC1 PHP PHP 5.1.3 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.0 candidate 3 PHP PHP 5.0 candidate 2 PHP PHP 5.0 candidate 1 PHP PHP 5.0 .0 PHP PHP 4.4.6 PHP PHP 4.4.5 PHP PHP 4.4.4 PHP PHP 4.4.3 PHP PHP 4.4.2 PHP PHP 4.4.1 PHP PHP 4.4 .0 PHP PHP 4.3.11 PHP PHP 4.3.10 PHP PHP 4.3.9 PHP PHP 4.3.8 PHP PHP 4.3.7 PHP PHP 4.3.6 PHP PHP 4.3.5 PHP PHP 4.3.4 PHP PHP 4.3.3 PHP PHP 4.3.2 PHP PHP 4.3.1 PHP PHP 4.3 PHP PHP 4.2.3 PHP PHP 4.2.2 PHP PHP 4.2.1 PHP PHP 4.2 .0 PHP PHP 4.2 -dev PHP PHP 4.1.2 PHP PHP 4.1.1 PHP PHP 4.1 .0 PHP PHP 4.0.7 RC3 PHP PHP 4.0.7 RC2 PHP PHP 4.0.7 RC1 PHP PHP 4.0.7 PHP PHP 4.0.6 PHP PHP 4.0.5 PHP PHP 4.0.4 PHP PHP 4.0.3 pl1 PHP PHP 4.0.3 PHP PHP 4.0.2 PHP PHP 4.0.1 pl2 PHP PHP 4.0.1 pl1 PHP PHP 4.0.1 PHP PHP 4.0 0 PHP PHP 3.0.18 PHP PHP 3.0.17 PHP PHP 3.0.16 PHP PHP 3.0.15 PHP PHP 3.0.14 PHP PHP 3.0.13 PHP PHP 3.0.12 PHP PHP 3.0.11 PHP PHP 3.0.10 PHP PHP 3.0.9 PHP PHP 3.0.8 PHP PHP 3.0.7 PHP PHP 3.0.6 PHP PHP 3.0.5 PHP PHP 3.0.4 PHP PHP 3.0.3 PHP PHP 3.0.2 PHP PHP 3.0.1 PHP PHP 3.0 0 PHP PHP 3.0 .16 PHP PHP 3.0 .13 PHP PHP 3.0 .12 PHP PHP 3.0 .11 PHP PHP 3.0 .10 PHP PHP 5.2 OpenPKG OpenPKG E1.0-Solid OpenPKG OpenPKG Current Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.3.9 Apple Mac OS X 10.4.10 Apple Mac OS X 10.3.9 |
| Not Vulnerable: |
PHP PHP 5.2.2 PHP PHP 4.4.7 |
Discussion
PHP BZip2/Zip Wrappers Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
PHP is prone to multiple 'safe_mode' and 'open_basedir' restriction-bypass vulnerabilities. Successful exploits could allow an attacker to access sensitive information or to write files in unauthorized locations.
These vulnerabilities would be issues in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code; in such cases, the 'safe_mode' and 'open_basedir' restrictions are expected to isolate users from each other.
PHP 5.2.1 and prior versions are vulnerable to these issues.
PHP is prone to multiple 'safe_mode' and 'open_basedir' restriction-bypass vulnerabilities. Successful exploits could allow an attacker to access sensitive information or to write files in unauthorized locations.
These vulnerabilities would be issues in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code; in such cases, the 'safe_mode' and 'open_basedir' restrictions are expected to isolate users from each other.
PHP 5.2.1 and prior versions are vulnerable to these issues.
Exploit / POC
PHP BZip2/Zip Wrappers Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
PHP BZip2/Zip Wrappers Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.4.10
Apple Mac OS X Server 10.4.10
PHP PHP 4.0 0
PHP PHP 4.0.1
PHP PHP 4.0.1 pl1
PHP PHP 4.0.1 pl2
PHP PHP 4.0.2
PHP PHP 4.0.3 pl1
PHP PHP 4.0.4
PHP PHP 4.0.6
PHP PHP 4.0.7
PHP PHP 4.0.7 RC1
PHP PHP 4.0.7 RC3
PHP PHP 4.1 .0
PHP PHP 4.1.1
PHP PHP 4.1.2
PHP PHP 4.2 -dev
PHP PHP 4.2.1
PHP PHP 4.2.2
PHP PHP 4.2.3
PHP PHP 4.3
PHP PHP 4.3.1
PHP PHP 4.3.10
PHP PHP 4.3.11
PHP PHP 4.3.2
PHP PHP 4.3.3
PHP PHP 4.3.4
PHP PHP 4.3.6
PHP PHP 4.3.9
PHP PHP 4.4 .0
PHP PHP 4.4.1
PHP PHP 4.4.2
PHP PHP 4.4.6
PHP PHP 5.0 .0
PHP PHP 5.0 candidate 2
PHP PHP 5.0.1
PHP PHP 5.0.5
PHP PHP 5.1
PHP PHP 5.1.2
PHP PHP 5.1.3 -RC1
PHP PHP 5.1.3
PHP PHP 5.1.5
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2007-007Pan.dmg For Mac OS X Server v10.3.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.4.10
-
Apple SecUpd2007-007Ti.dmg For Mac OS X v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpd2007-007Univ.dmg For Mac OS X v10.4.10 (Universal)
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.10
-
Apple SecUpdSrvr2007-007Ti.dmg For Mac OS X Server v10.4.10 (PowerPC)
http://www.apple.com/support/downloads/ -
Apple SecUpdSrvr2007-007Universal.dmg For Mac OS X Server v10.4.10 (Universal)
http://www.apple.com/support/downloads/
PHP PHP 4.0 0
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.1 pl1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.1 pl2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.3 pl1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.4
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.6
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.7
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.7 RC1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.0.7 RC3
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.1 .0
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.1.1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.1.2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.2 -dev
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.2.1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.2.2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.2.3
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.10
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.11
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.3
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.4
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.6
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.3.9
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.4 .0
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.4.1
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.4.2
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 4.4.6
-
PHP php-4.4.7-Win32.zip
http://www.php.net/get/php-4.4.7-Win32.zip/from/a/mirror -
PHP php-4.4.7.tar.bz2
http://www.php.net/get/php-4.4.7.tar.bz2/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0 .0
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0 candidate 2
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0.1
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.0.5
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.2
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.3 -RC1
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.3
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
PHP PHP 5.1.5
-
PHP php-5.2.2-win32-installer.msi
http://www.php.net/get/php-5.2.2-win32-installer.msi/from/a/mirror -
PHP php-5.2.2.tar.gz
http://www.php.net/get/php-5.2.2.tar.gz/from/a/mirror
References
PHP BZip2/Zip Wrappers Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
References:
References:
- MOPB-20-2007:PHP zip:// URL Wrapper safemode and open_basedir Bypass Vulnerabili (MOPB)
- MOPB-21-2007:PHP compress.bzip2:// URL Wrapper safemode and open_basedir Bypass (MOPB)
- PHP 4.4.7 Release Announcement (PHP)
- PHP 5.2.2 Release Announcement (PHP)
- PHP Homepage (PHP)
- SUSE Security Announcement: php4,php5 security problems (SUSE-SA:2007:032) (SUSE)