CVE-2014-3981: PHP

Low severity, CVSS 3.3. EPSS: 0.8% chance of exploitation in the next 30 days.

acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.

Affected products

  • PHP PHP: before 5.3.29 (fixed in 5.3.29); from 5.4.0, before 5.4.30 (fixed in 5.4.30); from 5.5.0, before 5.5.14 (fixed in 5.5.14)

Published 2014-06-08. Last modified 2026-06-17.