7.8
CVE-2015-5723
- EPSS 0.38%
- Veröffentlicht 07.06.2016 14:06:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zend ≫ Zend-cache Version <= 2.4.7
Zend ≫ Zend-cache Version 2.5.0
Zend ≫ Zend-cache Version 2.5.1
Zend ≫ Zend-cache Version 2.5.2
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Doctrine-project ≫ Object Relational Mapper Version <= 2.4.7
Doctrine-project ≫ Object Relational Mapper Version 2.5.0
Doctrine-project ≫ Object Relational Mapper Version 2.5.0 Update alpha1
Doctrine-project ≫ Object Relational Mapper Version 2.5.0 Update alpha2
Doctrine-project ≫ Object Relational Mapper Version 2.5.0 Update beta1
Doctrine-project ≫ Object Relational Mapper Version 2.5.0 Update rc1
Doctrine-project ≫ Object Relational Mapper Version 2.5.0 Update rc2
Doctrine-project ≫ Doctrinemongodbbundle Version 3.0.0
Zend ≫ Zend Framework Version <= 2.4.7
Doctrine-project ≫ Common Version <= 2.4.2
Doctrine-project ≫ Common Version 2.5.0
Doctrine-project ≫ Common Version 2.5.0 Update beta1
Doctrine-project ≫ Annotations Version <= 1.2.6
Doctrine-project ≫ Mongodb-odm Version <= 1.0.1
Zend ≫ Zend Framework Version <= 1.12.15
Doctrine-project ≫ Cache Version <= 1.3.1
Doctrine-project ≫ Cache Version 1.4.0
Doctrine-project ≫ Cache Version 1.4.1
Zend ≫ Zf-apigility-doctrine Version <= 1.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.3 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
http://framework.zend.com/security/advisory/ZF2015-07
http://www.debian.org/security/2015/dsa-3369
http://www.doctrine-project.org/2015/08/31/security_misconfiguration_vulnerability_in_various_doctrine_projects.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2IUUC7HPN4XE5NNTG4MR76OC662XRZUO/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HPS7A54FQ2CR6PH4NDR6UIYJIRNFXW67/