CVE Vulnerabilities

CVE-2007-1370

Published: Mar 09, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.2 MEDIUM
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modifying the files. NOTE: this only occurs when safe_mode and open_basedir are disabled; other settings require leverage for other vulnerabilities.

Affected Software

NameVendorStart VersionEnd Version
Zend_platformZend2.2.1a (including)2.2.1a (including)
Zend_platformZend2.2.1a-a (including)2.2.1a-a (including)

References