CVE-2008-5658

Impact:
Moderate
Public Date:
2008-12-04
Bugzilla:
474824: CVE-2008-5658 php: ZipArchive::extractTo() Directory Traversal Vulnerability

The MITRE CVE dictionary describes this issue as:

Directory traversal vulnerability in the ZipArchive::extractTo function in PHP 5.2.6 and earlier allows context-dependent attackers to write arbitrary files via a ZIP file with a file whose name contains .. (dot dot) sequences.

Find out more about CVE-2008-5658 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue did not affect PHP versions as shipped in Red Hat Enterprise Linux 2.1, 3, 4, and 5, and Red Hat Application Stack v1. PHP version in Red Hat Application Stack v2 was fixed via: https://rhn.redhat.com/errata/RHSA-2009-0350.html

Red Hat Security Errata

Platform Errata Release Date
Red Hat Application Stack v2 for Enterprise Linux (v.5) (php) RHSA-2009:0350 2009-04-14

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.