Index: vuln.xml =================================================================== RCS file: /home/pcvs/ports/security/vuxml/vuln.xml,v retrieving revision 1.1190 diff -u -r1.1190 vuln.xml --- vuln.xml 14 Oct 2006 12:32:43 -0000 1.1190 +++ vuln.xml 14 Oct 2006 15:11:15 -0000 @@ -34,6 +34,50 @@ --> + + php -- php_admin* bypass by ini_restore() + + + php4 + php5 + 0 + + + php4-cli + php5-cli + php4-cgi + php5-cgi + php4-dtc + php5-dtc + php4-horde + php5-horde + php4-nms + php5-nms + mod_php4 + mod_php5 + 0 + + + + +

Maksymilian Arciemowicz reports it is possible to bypass + Apache http.conf options, such as safe_mode and open_basedir, + using ini_restore() function to reset the options to their + Master Values, defined in php.ini

+ +
+ + http://securityreason.com/achievement_securityalert/42 + CVE-2006-4625 + 19933 + http://secunia.com/advisories/22282/ + + + 2006-09-05 + 2006-10-14 + +
+ google-earth -- heap overflow in the KML engine