CVE-2010-3436
published 2010-11-09CVE-2010-3436: fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.
PriorityP432medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
6.32%
92.8th percentile
fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| php | php | >= 5.2.0 < 5.2.15 | 5.2.15 |
| php | php | >= 5.3.0 < 5.3.4 | 5.3.4 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_ubuntu6.8MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP5 regression
vendor_ubuntu·2011-01-13·CVSS 5.0
CVE-2010-3436 [MEDIUM] PHP5 regression
Title: PHP5 regression
USN-1042-1 fixed vulnerabilities in PHP5. The fix for CVE-2010-3436
introduced a regression in the open_basedir restriction handling code.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that attackers might be able to bypass open_basedir()
restrictions by passing a specially crafted filename. (CVE-2010-3436)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2011-01-11·CVSS 6.8
CVE-2010-4409 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
It was discovered that an integer overflow in the XML UTF-8 decoding
code could allow an attacker to bypass cross-site scripting (XSS)
protections. This issue only affected Ubuntu 6.06 LTS, Ubuntu 8.04 LTS,
and Ubuntu 9.10. (CVE-2009-5016)
It was discovered that the XML UTF-8 decoding code did not properly
handle non-shortest form UTF-8 encoding and ill-formed subsequences
in UTF-8 data, which could allow an attacker to bypass cross-site
scripting (XSS) protections. (CVE-2010-3870)
It was discovered that attackers might be able to bypass open_basedir()
restrictions by passing a specially crafted filename. (CVE-2010-3436)
Maksymilian Arciemowicz discovered that a NULL pointer derefence in the
ZIP archive handling code could allow an attacker to cause a denial
Red Hat
php: open_basedir bypass via fopen_wrappers.c
vendor_redhat·2010-09-28·CVSS 5.0
CVE-2010-3436 [MEDIUM] php: open_basedir bypass via fopen_wrappers.c
php: open_basedir bypass via fopen_wrappers.c
fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.
Statement: We do not consider safe_mode / open_basedir restriction bypass issues to be security sensitive. For more details see http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1 and http://www.php.net/security-note.php
GHSA
GHSA-95jp-m7hw-782q: fopen_wrappers
ghsa_unreviewed·2022-05-17
CVE-2010-3436 [MEDIUM] GHSA-95jp-m7hw-782q: fopen_wrappers
fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://secunia.com/advisories/42729http://secunia.com/advisories/42812http://security-tracker.debian.org/tracker/CVE-2010-3436http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.490619http://support.apple.com/kb/HT4581http://support.apple.com/kb/HT5002http://svn.php.net/viewvc/php/php-src/trunk/main/fopen_wrappers.c?r1=303824&r2=303823&pathrev=303824http://svn.php.net/viewvc?view=revision&revision=303824http://www.mandriva.com/security/advisories?name=MDVSA-2010:218http://www.php.net/ChangeLog-5.phphttp://www.php.net/archive/2010.php#id2010-12-10-1http://www.php.net/releases/5_2_15.phphttp://www.php.net/releases/5_3_4.phphttp://www.securityfocus.com/bid/44723http://www.ubuntu.com/usn/USN-1042-1http://www.vupen.com/english/advisories/2010/3313http://www.vupen.com/english/advisories/2011/0077http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://secunia.com/advisories/42729http://secunia.com/advisories/42812http://security-tracker.debian.org/tracker/CVE-2010-3436http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.490619http://support.apple.com/kb/HT4581http://support.apple.com/kb/HT5002http://svn.php.net/viewvc/php/php-src/trunk/main/fopen_wrappers.c?r1=303824&r2=303823&pathrev=303824http://svn.php.net/viewvc?view=revision&revision=303824http://www.mandriva.com/security/advisories?name=MDVSA-2010:218http://www.php.net/ChangeLog-5.phphttp://www.php.net/archive/2010.php#id2010-12-10-1http://www.php.net/releases/5_2_15.phphttp://www.php.net/releases/5_3_4.phphttp://www.securityfocus.com/bid/44723http://www.ubuntu.com/usn/USN-1042-1http://www.vupen.com/english/advisories/2010/3313http://www.vupen.com/english/advisories/2011/0077
2010-11-09
Published