CVE-2014-0185

sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 24%
VendorProductVersion
phpphp
5.3.0 ≤
𝑥
< 5.3.28
phpphp
5.4.0 ≤
𝑥
< 5.4.28
phpphp
5.5.0 ≤
𝑥
< 5.5.12
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php5
trusty
Fixed 5.5.9+dfsg-1ubuntu4.1
released
saucy
Fixed 5.5.3+dfsg-1ubuntu2.4
released
quantal
ignored
precise
Fixed 5.3.10-1ubuntu3.12
released
lucid
not-affected