7.8

CVE-2015-5723

Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zend ≫ Zend-cache Version <= 2.4.7
Zend ≫ Zend-cache Version 2.5.0
Zend ≫ Zend-cache Version 2.5.1
Zend ≫ Zend-cache Version 2.5.2
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Doctrine-project ≫ Object Relational Mapper Version 2.5.0 Update alpha1
Doctrine-project ≫ Object Relational Mapper Version 2.5.0 Update alpha2
Doctrine-project ≫ Object Relational Mapper Version 2.5.0 Update beta1
Doctrine-project ≫ Object Relational Mapper Version 2.5.0 Update rc1
Doctrine-project ≫ Object Relational Mapper Version 2.5.0 Update rc2
Zend ≫ Zend Framework Version <= 2.4.7
Doctrine-project ≫ Common Version <= 2.4.2
Doctrine-project ≫ Common Version 2.5.0
Doctrine-project ≫ Common Version 2.5.0 Update beta1
Doctrine-project ≫ Annotations Version <= 1.2.6
Doctrine-project ≫ Mongodb-odm Version <= 1.0.1
Zend ≫ Zend Framework Version <= 1.12.15
Doctrine-project ≫ Cache Version <= 1.3.1
Doctrine-project ≫ Cache Version 1.4.0
Doctrine-project ≫ Cache Version 1.4.1
Zend ≫ Zf-apigility-doctrine Version <= 1.0.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.3
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://framework.zend.com/security/advisory/ZF2015-07
http://www.debian.org/security/2015/dsa-3369
http://www.doctrine-project.org/2015/08/31/security_misconfiguration_vulnerability_in_various_doctrine_projects.html
Vendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2IUUC7HPN4XE5NNTG4MR76OC662XRZUO/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HPS7A54FQ2CR6PH4NDR6UIYJIRNFXW67/