CVE-2007-0905

NameCVE-2007-0905
DescriptionPHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension. NOTE: it is possible that this issue is a duplicate of CVE-2006-6383.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs410561, 410995

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php5 (PTS)jessie, jessie (lts)5.6.40+dfsg-0+deb8u18fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php5source(unstable)5.2.0-9unimportant410561, 410995

Notes

we normally don't spend much time on safe_mode and open_basedir
issues, but the because the attack vectors are "unspecified", it
might be harder for us to try and sort out the fixes for this
from the session fixes in CVE-2007-0906 (see there for more info)

Search for package or bug name: Reporting problems