Bug 1269077 - (CVE-2015-5723) CVE-2015-5723 php-ZendFramework: filesystem permissions issues in multiple components (ZF2015-07)
CVE-2015-5723 php-ZendFramework: filesystem permissions issues in multiple co...
Status: CLOSED CURRENTRELEASE
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20150915,repor...
: Security
Depends On: 1269079 1269080 1269081
Blocks:
  Show dependency treegraph
 
Reported: 2015-10-06 05:19 EDT by Martin Prpič
Modified: 2016-08-09 03:13 EDT (History)
5 users (show)

See Also:
Fixed In Version: Zend Framework 1.12.16, Zend Framework 2.4.8
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-08-09 03:13:57 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Martin Prpič 2015-10-06 05:19:39 EDT
It was reported that incorrect permissions masks when creating a new directory or file can lead to local arbitrary code execution or privilege escalation.

This issue has been fixed in upstream versions 1.12.16 and 2.4.8.

External References:

http://framework.zend.com/security/advisory/ZF2015-07
Comment 1 Martin Prpič 2015-10-06 05:24:10 EDT
Created php-ZendFramework2 tracking bugs for this issue:

Affects: epel-6 [bug 1269079]
Comment 2 Martin Prpič 2015-10-06 05:24:13 EDT
Created php-ZendFramework tracking bugs for this issue:

Affects: epel-all [bug 1269080]
Affects: fedora-all [bug 1269081]
Comment 3 Fedora Update System 2016-08-08 17:48:18 EDT
php-ZendFramework2-2.2.10-2.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
Comment 4 Shawn Iwinski 2016-08-08 21:46:51 EDT
All dependent bugs closed

Note You need to log in before you can comment on or make changes to this bug.