CVE-2015-5723
Summary
| CVE | CVE-2015-5723 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-06-07 14:06:08 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code. |
Risk And Classification
Primary CVSS: v3.0 7.8 HIGH from [email protected]
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-264 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.2 | AV:L/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Doctrine-project | Annotations | All | All | All | All |
| Application | Doctrine-project | Cache | 1.4.0 | All | All | All |
| Application | Doctrine-project | Cache | 1.4.1 | All | All | All |
| Application | Doctrine-project | Cache | All | All | All | All |
| Application | Doctrine-project | Common | 2.5.0 | All | All | All |
| Application | Doctrine-project | Common | 2.5.0 | beta1 | All | All |
| Application | Doctrine-project | Common | All | All | All | All |
| Application | Doctrine-project | Doctrinemongodbbundle | 3.0.0 | All | All | All |
| Application | Doctrine-project | Mongodb-odm | All | All | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | All | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | alpha1 | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | alpha2 | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | beta1 | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | rc1 | All | All |
| Application | Doctrine-project | Object Relational Mapper | 2.5.0 | rc2 | All | All |
| Application | Doctrine-project | Object Relational Mapper | All | All | All | All |
| Application | Zend | Zend-cache | 2.5.0 | All | All | All |
| Application | Zend | Zend-cache | 2.5.1 | All | All | All |
| Application | Zend | Zend-cache | 2.5.2 | All | All | All |
| Application | Zend | Zend-cache | All | All | All | All |
| Application | Zend | Zend Framework | All | All | All | All |
| Application | Zend | Zend Framework | All | All | All | All |
| Application | Zend | Zf-apigility-doctrine | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ZF2015-07: Filesystem Permissions Issues in Multiple Components - Advisories - Security - Zend Framework | af854a3a-2127-422b-91ae-364da2661108 | framework.zend.com | |
| [SECURITY] Fedora 24 Update: php-doctrine-common-2.5.3-1.fc24 - package-announce - Fedora Mailing-Lists | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Security Misconfiguration Vulnerability in various Doctrine projects — Doctrine Project | af854a3a-2127-422b-91ae-364da2661108 | www.doctrine-project.org | Vendor Advisory |
| [SECURITY] Fedora 23 Update: php-doctrine-common-2.5.3-1.fc23 - package-announce - Fedora Mailing-Lists | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Debian -- Security Information -- DSA-3369-1 zendframework | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [SECURITY] Fedora 23 Update: php-doctrine-common-2.5.3-1.fc23 - package-announce - Fedora Mailing-Lists | MITRE | lists.fedoraproject.org | |
| [SECURITY] Fedora 24 Update: php-doctrine-common-2.5.3-1.fc24 - package-announce - Fedora Mailing-Lists | MITRE | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995894 PHP (Composer) Security Update for aws/aws-sdk-php (GHSA-pw5c-xqf2-6xc2)