CVE-2014-0185

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
06/05/2014
Last modified:
12/04/2025

Description

sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.3.0 (including) 5.3.28 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.4.0 (including) 5.4.28 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.5.0 (including) 5.5.12 (excluding)