CVE-2014-3981

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
08/06/2014
Last modified:
06/05/2026

Description

acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.3.29 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.4.0 (including) 5.4.30 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.5.0 (including) 5.5.14 (excluding)