CVE Vulnerabilities

CVE-2014-0185

Improper Privilege Management

Published: May 06, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
3.6 MODERATE
AV:L/AC:L/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp5.3.0 (including)5.3.28 (excluding)
PhpPhp5.4.0 (including)5.4.28 (excluding)
PhpPhp5.5.0 (including)5.5.12 (excluding)
Php5Ubuntuesm-infra-legacy/trusty*
Php5Ubuntuprecise*
Php5Ubuntuquantal*
Php5Ubuntusaucy*
Php5Ubuntutrusty*
Php5Ubuntutrusty/esm*

Potential Mitigations

References