PHP CVE-2012-1171 Security Bypass Vulnerability
BID:65673
Info
PHP CVE-2012-1171 Security Bypass Vulnerability
| Bugtraq ID: | 65673 |
| Class: | Design Error |
| CVE: |
CVE-2012-1171 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 12 2012 12:00AM |
| Updated: | Mar 12 2012 12:00AM |
| Credit: | Kurt Seifried |
| Vulnerable: |
PHP PHP 5.3.24 PHP PHP 5.3.23 PHP PHP 5.3.22 PHP PHP 5.3.21 PHP PHP 5.3.20 PHP PHP 5.3.17 PHP PHP 5.3.16 PHP PHP 5.3.14 PHP PHP 5.3.13 PHP PHP 5.3.12 PHP PHP 5.3.9 PHP PHP 5.3.8 PHP PHP 5.3.7 PHP PHP 5.3.6 PHP PHP 5.3.5 PHP PHP 5.3.2 PHP PHP 5.3.1 PHP PHP 5.3 PHP PHP 5.2.17 PHP PHP 5.2.16 PHP PHP 5.2.15 PHP PHP 5.2.13 PHP PHP 5.2.12 PHP PHP 5.2.11 PHP PHP 5.2.10 PHP PHP 5.2.9 -2 PHP PHP 5.2.9 PHP PHP 5.2.8 PHP PHP 5.2.7 PHP PHP 5.2.6 PHP PHP 5.2.5 PHP PHP 5.2.4 PHP PHP 5.2.3 PHP PHP 5.2.2 PHP PHP 5.2.1 PHP PHP 5.1.6 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 -RC1 PHP PHP 5.1.3 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.3.4 RC1 PHP PHP 5.3.4 PHP PHP 5.3.3 PHP PHP 5.3.27 PHP PHP 5.3.26 PHP PHP 5.3.25 PHP PHP 5.3.19 PHP PHP 5.3.18 PHP PHP 5.3.15 PHP PHP 5.3.11 PHP PHP 5.3.10 PHP PHP 5.2.14 PHP PHP 5.2 PHP PHP 5.1.43 |
| Not Vulnerable: | |
Discussion
PHP CVE-2012-1171 Security Bypass Vulnerability
PHP is prone to a security-bypass vulnerability.
Remote attackers can exploit this issue to bypass certain security restrictions and read arbitrary files in the context of the application.
PHP is prone to a security-bypass vulnerability.
Remote attackers can exploit this issue to bypass certain security restrictions and read arbitrary files in the context of the application.
Exploit / POC
PHP CVE-2012-1171 Security Bypass Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
PHP CVE-2012-1171 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
PHP CVE-2012-1171 Security Bypass Vulnerability
References:
References:
- CVE-2012-1171 php: libxml RSHUTDOWN function disables the hooks which are used (Red Hat Bugzilla)
- Bug #61367: open_basedir bypass in libxml RSHUTDOWN (The PHP Group)
- open_basedir bypass in libxml RSHUTDOWN (The PHP Group)
- PHP Homepage (PHP Group)