Wind River Support Network

HomeDefectsLIN10-3824
Fixed

LIN10-3824 : Security Advisory - php - CVE-2018-10545

Created: May 1, 2018    Updated: Dec 3, 2018
Resolved Date: May 20, 2018
Found In Version: 10.17.41.1
Fix Version: 10.17.41.8
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one user (in a multiuser environment) to obtain sensitive information from the process memory of a second user's PHP applications by running gcore on the PID of the PHP-FPM worker process.

https://nvd.nist.gov/vuln/detail/CVE-2018-10545

Other Downloads


CVEs


Live chat
Online