PDFLib 'open_basedir' Restriction Bypass Vulnerability
BID:36951
Info
PDFLib 'open_basedir' Restriction Bypass Vulnerability
| Bugtraq ID: | 36951 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 06 2009 12:00AM |
| Updated: | Nov 09 2009 03:16PM |
| Credit: | Sina Yazdanmehr (R3d.W0rm) |
| Vulnerable: |
PDFLib PDFLib 0 |
| Not Vulnerable: | |
Discussion
PDFLib 'open_basedir' Restriction Bypass Vulnerability
PDFLib is prone to an 'open_basedir' restriction-bypass vulnerability because it fails to properly enforce underlying PHP configuration directives.
Successful exploits could allow an attacker to write files in unauthorized locations.
This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code. In such cases, 'open_basedir' restrictions are expected to isolate users from each other.
Unknown versions of PDFLib running on PHP 5.3.0 are affected. We will update this BID when more details become available.
PDFLib is prone to an 'open_basedir' restriction-bypass vulnerability because it fails to properly enforce underlying PHP configuration directives.
Successful exploits could allow an attacker to write files in unauthorized locations.
This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code. In such cases, 'open_basedir' restrictions are expected to isolate users from each other.
Unknown versions of PDFLib running on PHP 5.3.0 are affected. We will update this BID when more details become available.
Exploit / POC
PDFLib 'open_basedir' Restriction Bypass Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
PDFLib 'open_basedir' Restriction Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PDFLib 'open_basedir' Restriction Bypass Vulnerability
References:
References: