CVE-2015-5723: Debian Linux
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Doctrine-Project Annotations: up to and including 1.2.6
- Doctrine-Project Cache: up to and including 1.3.1; version 1.4.0 only; version 1.4.1 only
- Doctrine-Project Common: up to and including 2.4.2; version 2.5.0 only
- Doctrine-Project Doctrinemongodbbundle: version 3.0.0 only
- Doctrine-Project MongoDB-Odm: up to and including 1.0.1
- Doctrine-Project Object Relational Mapper: up to and including 2.4.7; version 2.5.0 only
- Zend Zend-Cache: up to and including 2.4.7; version 2.5.0 only; version 2.5.1 only; version 2.5.2 only
- Zend Zend Framework: up to and including 2.4.7; up to and including 1.12.15
- Zend Zf-Apigility-Doctrine: up to and including 1.0.2
Published 2016-06-07. Last modified 2026-06-17.