Unrated severityNVD Advisory· Published Dec 17, 2008· Updated Apr 23, 2026
CVE-2008-5658
CVE-2008-5658
Description
Directory traversal vulnerability in the ZipArchive::extractTo function in PHP 5.2.6 and earlier allows context-dependent attackers to write arbitrary files via a ZIP file with a file whose name contains .. (dot dot) sequences.
Affected products
27cpe:2.3:a:php:php:*:*:*:*:*:*:*:*+ 26 more
- cpe:2.3:a:php:php:*:*:*:*:*:*:*:*range: <=5.2.6
- cpe:2.3:a:php:php:5.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.0.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.0.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.0.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.0.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.2.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
21- www.sektioneins.de/advisories/SE-2008-06.txtnvdExploit
- archives.neohapsis.com/archives/bugtraq/2008-12/0039.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.htmlnvd
- marc.infonvd
- marc.infonvd
- osvdb.org/50480nvd
- secunia.com/advisories/35003nvd
- secunia.com/advisories/35306nvd
- secunia.com/advisories/35650nvd
- wiki.rpath.com/Advisories:rPSA-2009-0035nvd
- www.debian.org/security/2009/dsa-1789nvd
- www.mandriva.com/security/advisoriesnvd
- www.openwall.com/lists/oss-security/2008/12/04/3nvd
- www.php.net/ChangeLog-5.phpnvd
- www.redhat.com/support/errata/RHSA-2009-0350.htmlnvd
- www.securityfocus.com/archive/1/501376/100/0/threadednvd
- www.securityfocus.com/bid/32625nvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/47079nvd
- www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.htmlnvd
News mentions
0No linked articles in our index yet.