CVE-2014-0185: PHP

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.

Affected products

  • PHP PHP: from 5.3.0, before 5.3.28 (fixed in 5.3.28); from 5.4.0, before 5.4.28 (fixed in 5.4.28); from 5.5.0, before 5.5.12 (fixed in 5.5.12)

Published 2014-05-06. Last modified 2026-06-17.