---
title: "CVE-2006-2660\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-2660?format=md
keywords: index, follow
---

# CVE-2006-2660

Publication date 13 June 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Buffer consumption vulnerability in the tempnam function in PHP 5.1.4 and
4.x before 4.4.3 allows local users to bypass restrictions and create PHP
files with fixed names in other directories via a pathname argument longer
than MAXPATHLEN, which prevents a unique string from being appended to the
filename.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| php5 | 7.04 feisty | Not affected |
| 6.10 edgy | Not affected |
| 6.06 LTS dapper | Fixed 5.1.2-1ubuntu3.9 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2660)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-2660)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-2660)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-2660)

### Related Ubuntu Security Notices (USN)

+ [USN-320-1](https://usn.ubuntu.com/USN-320-1)
+ PHP vulnerabilities
+ 19 July 2006

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-2660>
