CVE-2010-1129
The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function.
Date published : 2010-03-26
http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html