Bug 917302 (CVE-2013-6501) - VUL-0: CVE-2013-6501: php5,php53: predictible filename used for cache in world writable directory
Summary: VUL-0: CVE-2013-6501: php5,php53: predictible filename used for cache in worl...
Status: RESOLVED WONTFIX
Alias: CVE-2013-6501
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2015-03-03
Assignee: Petr Gajdos
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/113655/
Whiteboard: maint:running:60773:important CVSSv2:...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-02-11 09:46 UTC by Johannes Segitz
Modified: 2016-04-27 19:21 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2015-02-11 09:46:41 UTC
rh#1009103

The php wdsl extension is reading predictible filename from a cache directory (default /tmp). Could allow injection of WSDL file. For details please see the RH bug.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1009103
http://seclists.org/oss-sec/2015/q1/471
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6501
Comment 3 Swamp Workflow Management 2015-02-24 13:21:00 UTC
An update workflow for this issue was started.
This issue was rated as important.
Please submit fixed packages until 2015-03-03.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/60773