Bugzilla – Bug 917302
VUL-0: CVE-2013-6501: php5,php53: predictible filename used for cache in world writable directory
Last modified: 2016-04-27 19:21:45 UTC
rh#1009103 The php wdsl extension is reading predictible filename from a cache directory (default /tmp). Could allow injection of WSDL file. For details please see the RH bug. References: https://bugzilla.redhat.com/show_bug.cgi?id=1009103 http://seclists.org/oss-sec/2015/q1/471 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6501
An update workflow for this issue was started. This issue was rated as important. Please submit fixed packages until 2015-03-03. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/60773