Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2008-1734 Details

Description

Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphabetic name, which triggers interpretation of a certain unquoted [a-z] argument as a matching shell glob for this name, rather than interpretation as the literal [a-z] regular-expression string, and consequently blocks the launch of the PHP interpreter within the Apache HTTP Server.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-20Improper Input Validation[email protected]

Affected Products

ProductVersions
gentoo linux
All versions

CPE

  • cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
gentoo php toolkit
<= 1.0
1.0
1.0 rc2

CPE

  • cpe:2.3:a:gentoo:php_toolkit:*:rc1:*:*:*:*:*:*
  • cpe:2.3:a:gentoo:php_toolkit:1.0:*:*:*:*:*:*:*
  • cpe:2.3:a:gentoo:php_toolkit:1.0:rc2:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2008-1734
NVD Published Date:
Apr 18, 2008
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2008-1734 Details - Not Deferred