CVE-2004-1063
published 2005-01-10CVE-2004-1063: PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver, allows local users to bypass safe_mode_exec_dir…
PriorityP433critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.18%
89.8th percentile
PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver, allows local users to bypass safe_mode_exec_dir restrictions and execute commands outside of the intended safe_mode_exec_dir via shell metacharacters in the current directory name. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| php | php | 4.0.0 – 4.3.9 | — |
| php | php | 5.0.0 – 5.0.2 | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP4 vulnerabilities
vendor_ubuntu·2005-03-18
CVE-2004-1018 PHP4 vulnerabilities
Title: PHP4 vulnerabilities
Summary: PHP4 vulnerabilities
Stefano Di Paola discovered integer overflows in PHP's pack() and
unpack() functions. A malicious PHP script could exploit these to
break out of safe mode and execute arbitrary code with the privileges
of the PHP interpreter. (CAN-2004-1018)
Note: The second part of CAN-2004-1018 (buffer overflow in the
shmop_write() function) was already fixed in USN-66-1.
Stefan Esser discovered two safe mode bypasses which allowed malicious
PHP scripts to circumvent path restrictions. This was possible by
either using virtual_popen() with a current directory containing shell
metacharacters (CAN-2004-1063) or creating a specially crafted
directory whose length exceeded the capacity of the realpath()
function (CAN-2004-1064).
Instructions: In
Red Hat
CVE-2004-1063: PHP 4
vendor_redhat·CVSS 10.0
CVE-2004-1063 [CRITICAL] CVE-2004-1063: PHP 4
PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver, allows local users to bypass safe_mode_exec_dir restrictions and execute commands outside of the intended safe_mode_exec_dir via shell metacharacters in the current directory name. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.
Statement: We do not consider safe_mode / open_basedir restriction bypass issues being security sensitive. For more details see http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1 and http://www.php.net/security-note.php
GHSA
GHSA-8w9g-f9jw-3mqv: PHP 4
ghsa_unreviewed·2022-04-29
CVE-2004-1063 [HIGH] GHSA-8w9g-f9jw-3mqv: PHP 4
PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver, allows local users to bypass safe_mode_exec_dir restrictions and execute commands outside of the intended safe_mode_exec_dir via shell metacharacters in the current directory name. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000915http://www.gentoo.org/security/en/glsa/glsa-200412-14.xmlhttp://www.hardened-php.net/advisories/012004.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2004:151http://www.mandriva.com/security/advisories?name=MDKSA-2005:072http://www.osvdb.org/12412http://www.php.net/release_4_3_10.phphttp://www.securityfocus.com/advisories/9028http://www.securityfocus.com/archive/1/384545http://www.securityfocus.com/bid/11964https://exchange.xforce.ibmcloud.com/vulnerabilities/18511https://www.ubuntu.com/usn/usn-99-1/http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000915http://www.gentoo.org/security/en/glsa/glsa-200412-14.xmlhttp://www.hardened-php.net/advisories/012004.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2004:151http://www.mandriva.com/security/advisories?name=MDKSA-2005:072http://www.osvdb.org/12412http://www.php.net/release_4_3_10.phphttp://www.securityfocus.com/advisories/9028http://www.securityfocus.com/archive/1/384545http://www.securityfocus.com/bid/11964https://exchange.xforce.ibmcloud.com/vulnerabilities/18511https://www.ubuntu.com/usn/usn-99-1/
2005-01-10
Published