[php-maint] Bug#605391: Patch for CVE-2010-3436 breaks open_basedir

Ruben Puettmann ruben at puettmann.net
Mon Nov 29 14:34:55 UTC 2010


Package: php5
Version: 5.3.3-4
Severity: normal


            hy,


the patch which was added cause CVE-2010-3436 breaks configurations. 
If you have set:

open_basedir=/srv/www/
 
it breaks. You must now set open_basedir=/srv/www without the ending /.

        
                Ruben


-- 
Ruben Puettmann
ruben at puettmann.net
http://www.puettmann.net
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 198 bytes
Desc: Digital signature
URL: <http://lists.alioth.debian.org/pipermail/pkg-php-maint/attachments/20101129/c822d4af/attachment.pgp>


More information about the pkg-php-maint mailing list