VDB
CVE-2009-4018
CVE-2009-4018
PUBLISHED
CVSS 7.5 HIGH
The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable.
EPSS 22.31% · 95.9th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
22.31%
95.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| php | php | 1.0, 3.0, 3.0.1 |
Timeline
- Nov 27, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- 40262 third-party-advisory
- oval:org.mitre.oval:def:7256 vdb
- HPSBUX02543 vendor-advisory
- http://svn.php.net/viewvc/php/php-src/branches/PHP_5_2/ext/standard/proc_open.c?r1=286360&r2=286359&pathrev=286360 url
- [oss-security] 20091123 Re: CVE request: php 5.3.1 - proc_open() bypass PHP Bug #49026 [was: Re: CVE request: php 5.3.1 update] mailing-list
- 41490 third-party-advisory
- [oss-security] 20091123 Re: CVE request: php 5.3.1 - proc_open() bypass PHP Bug #49026 [was: Re: CVE request: php 5.3.1 update] mailing-list
- HPSBMA02568 vendor-advisory
- http://www.php.net/ChangeLog-5.php url
- 37138 vdb
- http://bugs.php.net/bug.php?id=49026 url
- 41480 third-party-advisory
- [oss-security] 20091122 Re: CVE request: php 5.3.1 update mailing-list
- http://svn.php.net/viewvc/?view=revision&revision=286360 url
- http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/standard/proc_open.c?r1=286360&r2=286359&pathrev=286360 url
- MDVSA-2009:303 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-4018 advisory