Wind River Support Network

HomeDefectsLIN9-6786
Fixed

LIN9-6786 : Security Advisory - php - CVE-2018-10545

Created: May 1, 2018    Updated: Dec 3, 2018
Resolved Date: May 27, 2018
Found In Version: 9.0.0.15
Fix Version: 9.0.0.16
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Userspace

Description

An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one user (in a multiuser environment) to obtain sensitive information from the process memory of a second user's PHP applications by running gcore on the PID of the PHP-FPM worker process.

https://nvd.nist.gov/vuln/detail/CVE-2018-10545

Other Downloads


CVEs


Live chat
Online