phpSysInfo: arbitrary code execution and directory traversal phpSysInfo contains two vulnerabilities that can allow arbitrary code execution and local directory traversal. phpSysInfo 2003-11-22 2007-12-30 26782 local 2.1-r1 2.1

phpSysInfo is a PHP system information tool.

phpSysInfo contains two vulnerabilities which could allow local files to be read or arbitrary PHP code to be executed, under the privileges of the web server process.

An attacker could read local files or execute arbitrary code with the permissions of the user running the host web server.

There is no known workaround at this time.

It is recommended that all Gentoo Linux users who are running www-apps/phpsysinfo upgrade to the fixed version:

# emerge sync # emerge -pv '>=www-apps/phpsysinfo-2.1-r1' # emerge '>=www-apps/phpsysinfo-2.1-r1' # emerge clean
CAN-2003-0536