CVE-2015-5723
Summary
| CVE | CVE-2015-5723 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-06-07 14:06:00 UTC |
| Updated | 2023-11-07 02:26:00 UTC |
| Description | Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Doctrine-project | Annotations | All | All | All | All |
| Application | Doctrine-project | Cache | 1.4.0 | All | All | All |
| Application | Doctrine-project | Cache | 1.4.1 | All | All | All |
| Application | Doctrine-project | Cache | 1.4.0 | All | All | All |
| Application | Doctrine-project | Cache | 1.4.1 | All | All | All |
| Application | Doctrine-project | Cache | All | All | All | All |
| Application | Doctrine-project | Common | 2.5.0 | All | All | All |
| Application | Doctrine-project | Common | 2.5.0 | beta1 | All | All |
| Application | Doctrine-project | Common | 2.5.0 | All | All | All |
| Application | Doctrine-project | Common | 2.5.0 | beta1 | All | All |
| Application | Doctrine-project | Common | All | All | All | All |
| Application | Doctrine-project | Doctrinemongodbbundle | 3.0.0 | All | All | All |
| Application | Doctrine-project | Doctrinemongodbbundle | 3.0.0 | All | All | All |
| Application | Doctrine-project | Mongodb-odm | All | All | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | All | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | alpha1 | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | alpha2 | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | beta1 | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | rc1 | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | rc2 | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | All | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | alpha1 | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | alpha2 | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | beta1 | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | rc1 | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | rc2 | All | All |
| Application | Doctrine-project | Object Relational Mapper | All | All | All | All |
| Application | Zend | Zend-cache | 2.5.0 | All | All | All |
| Application | Zend | Zend-cache | 2.5.1 | All | All | All |
| Application | Zend | Zend-cache | 2.5.2 | All | All | All |
| Application | Zend | Zend-cache | 2.5.0 | All | All | All |
| Application | Zend | Zend-cache | 2.5.1 | All | All | All |
| Application | Zend | Zend-cache | 2.5.2 | All | All | All |
| Application | Zend | Zend-cache | All | All | All | All |
| Application | Zend | Zend Framework | All | All | All | All |
| Application | Zend | Zend Framework | All | All | All | All |
| Application | Zend | Zf-apigility-doctrine | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-3369-1 zendframework | DEBIAN | www.debian.org | |
| ZF2015-07: Filesystem Permissions Issues in Multiple Components - Advisories - Security - Zend Framework | CONFIRM | framework.zend.com | |
| Security Misconfiguration Vulnerability in various Doctrine projects — Doctrine Project | CONFIRM | www.doctrine-project.org | Vendor Advisory |
| [SECURITY] Fedora 24 Update: php-doctrine-common-2.5.3-1.fc24 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 23 Update: php-doctrine-common-2.5.3-1.fc23 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 24 Update: php-doctrine-common-2.5.3-1.fc24 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 23 Update: php-doctrine-common-2.5.3-1.fc23 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995894 PHP (Composer) Security Update for aws/aws-sdk-php (GHSA-pw5c-xqf2-6xc2)