---
title: "CVE-2008-7002\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2008-7002?format=md
keywords: index, follow
---

# CVE-2008-7002

Publication date 19 August 2009

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

PHP 5.2.5 does not enforce (a) open\_basedir and (b) safe\_mode\_exec\_dir
restrictions for certain functions, which might allow local users to bypass
intended access restrictions and call programs outside of the intended
directory via the (1) exec, (2) system, (3) shell\_exec, (4) passthru, or
(5) popen functions, possibly involving pathnames such as "C:" drive
notation.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2008-7002?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| php5 | 9.04 jaunty | Ignored |
| 8.10 intrepid | Ignored |
| 8.04 LTS hardy | Ignored |
| 6.06 LTS dapper | Ignored |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

PoC at http://downloads.securityfocus.com/vulnerabilities/exploits/31064.php

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

The "PoC" doesn't turn on safe\_mode, so of course
safe\_mode\_exec\_dir doesn't work. Ignoring.

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7002)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2008-7002)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2008-7002)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2008-7002)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2008-7002>
