PT-2011-2344 · Debian+1 · Debian+1

Publicado

2011-03-29

·

Atualizado

2017-08-17

·

CVE-2011-0441

CVSS v2.0

6.3

Média

VetorAV:L/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP version 5.3.5
Description The issue allows local users to delete arbitrary files via a symlink attack on a directory under /var/lib/php5/. This is related to the Debian GNU/Linux /etc/cron.d/php5 cron job.
Recommendations For PHP version 5.3.5, consider restricting access to the /var/lib/php5/ directory to prevent symlink attacks until a patch is available. As a temporary workaround, monitor the cron job's activity closely to detect any potential misuse.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-0441
DSA-2195-1

Produtos afetados

Debian
Php