{"id":"CVE-2018-15132","details":"An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The linkinfo function on Windows doesn't implement the open_basedir check. This could be abused to find files on paths outside of the allowed directories.","modified":"2026-07-08T14:14:39.283808Z","published":"2018-08-07T15:29:00.873Z","references":[{"type":"ADVISORY","url":"http://php.net/ChangeLog-5.php"},{"type":"ADVISORY","url":"http://php.net/ChangeLog-7.php"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20181107-0003/"},{"type":"ADVISORY","url":"https://www.tenable.com/security/tns-2018-12"},{"type":"FIX","url":"https://github.com/php/php-src/commit/f151e048ed27f6f4eef729f3310d053ab5da71d4"},{"type":"EVIDENCE","url":"https://bugs.php.net/bug.php?id=76459"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/php/php-src","events":[{"introduced":"0"},{"fixed":"ea179bc44506ae1a4d5bb90502e962f43a902071"},{"introduced":"60fffd296abce5fc071f3c173c25a2696cf683c6"},{"fixed":"36d3d6c97c7d38a4d21438b5efa20f0b309518dd"},{"introduced":"0221e9f827632942225586687a33cfd554860d5e"},{"fixed":"1ceec3e87fa898ae09eb2d67353713f5bc0202bc"},{"introduced":"8148cbb78841c8ec0759c0836e7f35dec799d300"},{"fixed":"e32dc9aab87e888eefa7461dd71023d8274bb82d"},{"fixed":"f151e048ed27f6f4eef729f3310d053ab5da71d4"}],"database_specific":{"cpe":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"5.6.37"},{"introduced":"7.0.0"},{"fixed":"7.0.31"},{"introduced":"7.1.0"},{"fixed":"7.1.20"},{"introduced":"7.2.0"},{"fixed":"7.2.8"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["POST_PHP7_NSAPI_REMOVAL","PRE_PHP7_NSAPI_REMOVAL","PRE_PHP7_EREG_MYSQL_REMOVALS","PRE_PHP7_REMOVALS","POST_PHP7_REMOVALS","POST_AST_MERGE","PRE_AST_MERGE","POST_64BIT_BRANCH_MERGE","PRE_64BIT_BRANCH_MERGE","POST_PHPNG_MERGE"],"database_specific":{"vanir_signatures":[{"source":"https://github.com/php/php-src/commit/f151e048ed27f6f4eef729f3310d053ab5da71d4","target":{"file":"ext/standard/link_win32.c","function":"PHP_FUNCTION"},"deprecated":false,"digest":{"function_hash":"220839560800956806208306563125284300441","length":336},"id":"CVE-2018-15132-168c6b48","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/php/php-src/commit/f151e048ed27f6f4eef729f3310d053ab5da71d4","target":{"file":"ext/standard/link_win32.c"},"deprecated":false,"digest":{"line_hashes":["212981070074641104509450091836034142668","88395583671409793582864696691747015255","135003533747648975021546284778785516302","35499557418267422634095220243727042900","117851673981305499478844129398245467257","305333203988229800397156101482248605558","81910444167263063639751966488804618110","74540981037737713416730411259175941424","40995403751221392183520592881069357352","6280604222098253175767719674684668033","301255860765288804387653980432627650299","288880281421390955004434485443976198059"],"threshold":0.9},"id":"CVE-2018-15132-dcccf7e0","signature_type":"Line","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-15132.json","vanir_signatures_modified":"2026-07-08T14:14:39Z"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}