CVE-2014-0185

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.

References

http://lists.opensuse.org/opensuse-updates/2015-10/msg00012.html

http://secunia.com/advisories/59061

http://secunia.com/advisories/59329

http://support.apple.com/kb/HT6443

http://www.openwall.com/lists/oss-security/2014/04/29/5

http://www.php.net/archive/2014.php#id2014-05-01-1

http://www.php.net/ChangeLog-5.php

https://bugs.launchpad.net/ubuntu/+source/php5/+bug/1307027

https://bugs.php.net/bug.php?id=67060

https://bugzilla.redhat.com/show_bug.cgi?id=1092815

https://github.com/php/php-src/commit/35ceea928b12373a3b1e3eecdc32ed323223a40d

https://hoffmann-christian.info/files/php-fpm/0001-Fix-bug-67060-use-default-mode-of-660.patch

Details

Source: MITRE

Published: 2014-05-06

Updated: 2017-01-07

Type: CWE-264

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

Tenable Plugins

View all (17 total)

IDNameProductFamilySeverity
86286openSUSE Security Update : froxlor (openSUSE-2015-636)NessusSuSE Local Security Checks
high
82333Mandriva Linux Security Advisory : php (MDVSA-2015:080)NessusMandriva Local Security Checks
high
9096PHP 5.4.x < 5.4.28 / 5.5.x < 5.5.12 Privilege EscalationNessus Network MonitorWeb Servers
medium
78556PHP 5.6.0 Multiple VulnerabilitiesNessusCGI abuses
high
8394Mac OS X < 10.9.5 Multiple Vulnerabilities (Security Update 2014-004)Nessus Network MonitorWeb Clients
critical
77748Mac OS X 10.9.x < 10.9.5 Multiple VulnerabilitiesNessusMacOS X Local Security Checks
critical
77455GLSA-201408-11 : PHP: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
76249Ubuntu 13.10 / 14.04 LTS : php5 updates (USN-2254-2)NessusUbuntu Local Security Checks
high
76201Ubuntu 10.04 LTS / 12.04 LTS / 13.10 / 14.04 LTS : php5 vulnerabilities (USN-2254-1)NessusUbuntu Local Security Checks
high
75385openSUSE Security Update : php5 (openSUSE-SU-2014:0784-1)NessusSuSE Local Security Checks
high
74380Slackware 13.0 / 13.1 / 13.37 / 14.0 / 14.1 / current : php (SSA:2014-160-01)NessusSlackware Local Security Checks
high
74279Debian DSA-2943-1 : php5 - security updateNessusDebian Local Security Checks
high
74029Mandriva Linux Security Advisory : php (MDVSA-2014:087)NessusMandriva Local Security Checks
high
73956Fedora 19 : php-5.5.12-1.fc19 (2014-5984)NessusFedora Local Security Checks
high
73880Fedora 20 : php-5.5.12-1.fc20 (2014-5960)NessusFedora Local Security Checks
high
73863PHP 5.5.x < 5.5.12 FPM Unix Socket Insecure Permission EscalationNessusCGI abuses
high
73862PHP 5.4.x < 5.4.28 FPM Unix Socket Insecure Permission EscalationNessusCGI abuses
high