CVE-2014-0185: PHP
High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.
sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.
Affected products
- PHP PHP: from 5.3.0, before 5.3.28 (fixed in 5.3.28); from 5.4.0, before 5.4.28 (fixed in 5.4.28); from 5.5.0, before 5.5.12 (fixed in 5.5.12)
Published 2014-05-06. Last modified 2026-06-17.