CVE Vulnerabilities

CVE-2014-0185

Improper Privilege Management

Published: May 06, 2014 | Modified: Aug 16, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Php Php 5.3.0 (including) 5.3.28 (excluding)
Php Php 5.4.0 (including) 5.4.28 (excluding)
Php Php 5.5.0 (including) 5.5.12 (excluding)

Potential Mitigations

References