Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modifying the files. NOTE: this only occurs when safe_mode and open_basedir are disabled; other settings require leverage for other vulnerabilities.
Link | Tags |
---|---|
http://www.php-security.org/MOPB/BONUS-06-2007.html | patch vendor advisory |
http://www.vupen.com/english/advisories/2007/0829 | vdb entry |
http://www.osvdb.org/32772 | vdb entry |
http://www.securityfocus.com/bid/22801 | vdb entry |
http://secunia.com/advisories/24501 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/32825 | vdb entry |
http://www.zend.com/products/zend_platform/security_vulnerabilities | vendor advisory |