CVE-2008-0599
05.05.2008, 17:20
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.Enginsight
Vendor | Product | Version |
---|---|---|
php | php | 𝑥 < 5.2.6 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 7.04 |
canonical | ubuntu_linux | 7.10 |
canonical | ubuntu_linux | 8.04 |
apple | mac_os_x | 𝑥 < 10.5.4 |
apple | mac_os_x_server | 𝑥 < 10.5.4 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration