Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-4850

Опубликовано: 25 янв. 2008
Источник: ubuntu
Приоритет: negligible
EPSS Средний
CVSS2: 5

Описание

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

edgy

ignored

end of life, was needed
feisty

DNE

gutsy

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

upstream

needed

Показывать по

РелизСтатусПримечание
dapper

not-affected

devel

released

5.2.6-1ubuntu4
edgy

ignored

end of life, was needed
feisty

released

5.2.1-0ubuntu1.6
gutsy

released

5.2.3-1ubuntu6.4
hardy

released

5.2.4-2ubuntu5.3
intrepid

released

5.2.6-1ubuntu4
jaunty

released

5.2.6-1ubuntu4
karmic

released

5.2.6-1ubuntu4
upstream

released

5.2.6

Показывать по

EPSS

Процентиль: 93%
0.10153
Средний

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 17 лет назад

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.

nvd
больше 17 лет назад

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.

debian
больше 17 лет назад

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5. ...

github
около 3 лет назад

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.

EPSS

Процентиль: 93%
0.10153
Средний

5 Medium

CVSS2