Name | CVE-2014-0185 |
Description | sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-2943-1 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
php5 | source | squeeze | (not affected) | |||
php5 | source | wheezy | 5.4.4-14+deb7u10 | DSA-2943-1 | ||
php5 | source | (unstable) | 5.5.12+dfsg-1 |
[squeeze] - php5 <not-affected> (FPM SAPI only enabled in 5.3.5-1)
https://bugs.php.net/bug.php?id=67060