CVE-2004-1064
published 2005-01-10CVE-2004-1064: The safe mode checks in PHP 4.x to 4.3.9 and PHP 5.x to 5.0.2 truncate the file path before passing the data to the realpath function, which could allow…
PriorityP427critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.74%
88.6th percentile
The safe mode checks in PHP 4.x to 4.3.9 and PHP 5.x to 5.0.2 truncate the file path before passing the data to the realpath function, which could allow attackers to bypass safe mode. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| php | php | 4.0.0 – 4.3.9 | — |
| php | php | 5.0.0 – 5.0.2 | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h3x9-2c56-jqm5: The safe mode checks in PHP 4
ghsa_unreviewed·2022-04-29
CVE-2004-1064 [HIGH] GHSA-h3x9-2c56-jqm5: The safe mode checks in PHP 4
The safe mode checks in PHP 4.x to 4.3.9 and PHP 5.x to 5.0.2 truncate the file path before passing the data to the realpath function, which could allow attackers to bypass safe mode. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.
Ubuntu
Fixed php4 packages for USN-99-1
vendor_ubuntu·2005-03-24
CVE-2004-1064 Fixed php4 packages for USN-99-1
Title: Fixed php4 packages for USN-99-1
Summary: Fixed php4 packages for USN-99-1
USN-99-1 fixed a safe mode bypass which allowed malicious PHP scripts
to circumvent path restrictions by creating a specially crafted
directory whose length exceeded the capacity of the realpath()
function (CAN-2004-1064). However, this caused severe regressions,
some applications like SquirrelMail and Gallery did not work any
more, and the package 'php4-pear' was empty. The current version
repairs this.
In addition this update fixes a crash of the PHP interpreter if
curl_init() was called with a non-string argument. Please note that
this is not security relevant since this condition usually cannot be
triggered externally.
Instructions: In general, a standard system update will make all the necessary chan
Ubuntu
PHP4 vulnerabilities
vendor_ubuntu·2005-03-18
CVE-2004-1018 PHP4 vulnerabilities
Title: PHP4 vulnerabilities
Summary: PHP4 vulnerabilities
Stefano Di Paola discovered integer overflows in PHP's pack() and
unpack() functions. A malicious PHP script could exploit these to
break out of safe mode and execute arbitrary code with the privileges
of the PHP interpreter. (CAN-2004-1018)
Note: The second part of CAN-2004-1018 (buffer overflow in the
shmop_write() function) was already fixed in USN-66-1.
Stefan Esser discovered two safe mode bypasses which allowed malicious
PHP scripts to circumvent path restrictions. This was possible by
either using virtual_popen() with a current directory containing shell
metacharacters (CAN-2004-1063) or creating a specially crafted
directory whose length exceeded the capacity of the realpath()
function (CAN-2004-1064).
Instructions: In
Red Hat
CVE-2004-1064: The safe mode checks in PHP 4
vendor_redhat·CVSS 10.0
CVE-2004-1064 [CRITICAL] CVE-2004-1064: The safe mode checks in PHP 4
The safe mode checks in PHP 4.x to 4.3.9 and PHP 5.x to 5.0.2 truncate the file path before passing the data to the realpath function, which could allow attackers to bypass safe mode. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.
Statement: We do not consider safe_mode / open_basedir restriction bypass issues being security sensitive. For more details see http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1 and http://www.php.net/security-note.php
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000915http://www.gentoo.org/security/en/glsa/glsa-200412-14.xmlhttp://www.hardened-php.net/advisories/012004.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2004:151http://www.mandriva.com/security/advisories?name=MDKSA-2005:072http://www.php.net/release_4_3_10.phphttp://www.securityfocus.com/advisories/9028http://www.securityfocus.com/archive/1/384545http://www.securityfocus.com/bid/11964https://exchange.xforce.ibmcloud.com/vulnerabilities/18512https://www.ubuntu.com/usn/usn-99-1/https://www.ubuntu.com/usn/usn-99-2/http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000915http://www.gentoo.org/security/en/glsa/glsa-200412-14.xmlhttp://www.hardened-php.net/advisories/012004.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2004:151http://www.mandriva.com/security/advisories?name=MDKSA-2005:072http://www.php.net/release_4_3_10.phphttp://www.securityfocus.com/advisories/9028http://www.securityfocus.com/archive/1/384545http://www.securityfocus.com/bid/11964https://exchange.xforce.ibmcloud.com/vulnerabilities/18512https://www.ubuntu.com/usn/usn-99-1/https://www.ubuntu.com/usn/usn-99-2/
2005-01-10
Published