MGASA-2014-0215
Dashboard / Vulnerabilities / MGASA-2014-0215
Summary: Updated php packages fix CVE-2014-0185
Details: Updated php packages fix security vulnerability: PHP FPM in PHP versions before 5.4.28 and 5.5.12 uses a UNIX domain socket with world-writable permissions by default, which allows any local user to connect to it and execute PHP scripts as the apache user (CVE-2014-0185). Additionally updated php-suhosin package corrects an issue which could cause a segfault in apache. Also updated is php-timezonedb.
References: https://advisories.mageia.org/MGASA-2014-0215.html, http://openwall.com/lists/oss-security/2014/04/29/5, http://www.php.net/ChangeLog-5.php#5.4.28, http://www.php.net/ChangeLog-5.php#5.5.12, https://lists.fedoraproject.org/pipermail/package-announce/2014-May/132546.html, https://bugs.mageia.org/show_bug.cgi?id=13290
Affected packages
Package
Name: php
Purl: pkg:rpm/mageia/php?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
