PT-2009-6202 · Php+1 · Php+1

Published

2009-11-27

·

Updated

2018-10-30

·

CVE-2009-4018

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.2.11 PHP versions 5.3.x prior to 5.3.1
Description The issue concerns the proc open function in PHP, which fails to enforce certain directives. This allows attackers to execute programs with an arbitrary environment via the env parameter. For example, a crafted value of the LD LIBRARY PATH environment variable can be used for exploitation.
Recommendations For PHP versions prior to 5.2.11, update to version 5.2.11 or later. For PHP versions 5.3.x prior to 5.3.1, update to version 5.3.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4018
HPSBUX02543

Affected Products

Hp-Ux
Php