Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-5723

Опубликовано: 07 июн. 2016
Источник: debian

Описание

Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php-doctrine-annotationsfixed1.2.7-1package
php-doctrine-annotationsfixed1.2.1-1+deb8u1jessiepackage
php-doctrine-cachefixed1.4.2-1package
php-doctrine-cachefixed1.3.1-1+deb8u1jessiepackage
php-doctrine-commonfixed2.5.1-1experimentalpackage
php-doctrine-commonfixed2.4.3-1package
php-doctrine-commonfixed2.4.2-2+deb8u1jessiepackage
doctrinefixed2.5.1+dfsg-1experimentalpackage
doctrinefixed2.4.8-1package
doctrinefixed2.4.6-1+deb8u1jessiepackage
doctrineno-dsawheezypackage
doctrineno-dsasqueezepackage
aws-sdk-for-phpfixed3.2.1-1experimentalpackage
aws-sdk-for-phpnot-affectedpackage
php-doctrine-bundlefixed1.5.2-1package
zendframeworkfixed1.12.16+dfsg-1package
zendframeworknot-affectedsqueezepackage

Примечания

  • Review of zendframework 1.10.6 in Squeeze found no usage of default unsafe permission except in library/Zend/Search/Lucene/Storage/Directory/Filesystem.php but which is unlikely to cause a security issue.

  • http://www.doctrine-project.org/2015/08/31/security_misconfiguration_vulnerability_in_various_doctrine_projects.html

  • https://github.com/aws/aws-sdk-php/releases/tag/3.2.1

  • http://framework.zend.com/security/advisory/ZF2015-07

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 9 лет назад

Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.

CVSS3: 7.8
nvd
больше 9 лет назад

Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.

CVSS3: 7.8
github
больше 3 лет назад

Doctrine Security Misconfiguration Vulnerability