CVE-2006-4481

Publication date 31 August 2006

Last updated 17 July 2025


Ubuntu priority

The (1) file_exists and (2) imap_reopen functions in PHP before 5.1.5 do not check for the safe_mode and open_basedir settings, which allows local users to bypass the settings. NOTE: the error_log function is covered by CVE-2006-3011, and the imap_open function is covered by CVE-2006-1017.

Status

Package Ubuntu Release Status
php5 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Fixed 5.1.2-1ubuntu3.9

References

Related Ubuntu Security Notices (USN)

    • USN-342-1
    • PHP vulnerabilities
    • 7 September 2006

Other references