SB2012072522 - Permissions, Privileges, and Access Controls in php (Alpine package)
Published: July 25, 2012
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2012-3365)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=08fffe9a968660587cea5659d1d7e1c0cad15b6e
- https://git.alpinelinux.org/aports/commit/?id=13fc90f3d7b3457447df4caa12628505bea6fc9e
- https://git.alpinelinux.org/aports/commit/?id=d0fc255e5c7fd2c969eb7dd64e76bed93e761745
- https://git.alpinelinux.org/aports/commit/?id=b9d1b15acff7eb38e5adec24faeaabf92cf93390