Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-21703

Опубликовано: 25 окт. 2021
Источник: ubuntu
Приоритет: high
EPSS Низкий
CVSS2: 6.9
CVSS3: 7.8

Описание

In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the child processes to access memory shared with the main process and write to it, modifying it in a way that would cause the root process to conduct invalid memory reads and writes, which can be used to escalate privileges from local unprivileged user to the root user.

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

released

5.5.9+dfsg-1ubuntu4.29+esm15
esm-infra/focal

DNE

focal

DNE

hirsute

DNE

impish

DNE

jammy

DNE

trusty

ignored

end of standard support
trusty/esm

released

5.5.9+dfsg-1ubuntu4.29+esm15

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

released

7.0.33-0ubuntu0.16.04.16+esm2
focal

DNE

hirsute

DNE

impish

DNE

jammy

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

released

7.2.24-0ubuntu0.18.04.10
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

released

7.2.24-0ubuntu0.18.04.10
esm-infra/focal

DNE

focal

DNE

hirsute

DNE

impish

DNE

jammy

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

released

7.4.3-4ubuntu2.7
focal

released

7.4.3-4ubuntu2.7
hirsute

released

7.4.16-1ubuntu2.2
impish

DNE

jammy

DNE

trusty

DNE

trusty/esm

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

hirsute

DNE

impish

released

8.0.8-1ubuntu0.1
jammy

DNE

trusty

DNE

trusty/esm

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

not-affected

8.1.0-1
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

jammy

not-affected

8.1.0-1
precise/esm

DNE

Показывать по

EPSS

Процентиль: 34%
0.00133
Низкий

6.9 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 6.4
redhat
около 4 лет назад

In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the child processes to access memory shared with the main process and write to it, modifying it in a way that would cause the root process to conduct invalid memory reads and writes, which can be used to escalate privileges from local unprivileged user to the root user.

CVSS3: 7.8
nvd
около 4 лет назад

In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the child processes to access memory shared with the main process and write to it, modifying it in a way that would cause the root process to conduct invalid memory reads and writes, which can be used to escalate privileges from local unprivileged user to the root user.

CVSS3: 7.8
msrc
около 1 месяца назад

PHP-FPM memory access in root process leading to privilege escalation

CVSS3: 7.8
debian
около 4 лет назад

In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 a ...

suse-cvrf
почти 4 года назад

Security update for php72

EPSS

Процентиль: 34%
0.00133
Низкий

6.9 Medium

CVSS2

7.8 High

CVSS3