VulnerabilityModified
CVE-2007-1370
Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modifying the files.
MEDIUM 6.2EPSS 0.30%
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modifying the files. NOTE: this only occurs when safe_mode and open_basedir are disabled; other settings require leverage for other vulnerabilities.
- CVSS 2.0
- 6.2 MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
- EPSS
- 0.30% probability · 22th percentile
- CISA KEV
- Not listed
- Affected
- zend/zend platform
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/24501
- http://www.osvdb.org/32772
- http://www.php-security.org/MOPB/BONUS-06-2007.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/22801
- http://www.vupen.com/english/advisories/2007/0829
- http://www.zend.com/products/zend_platform/security_vulnerabilitiesVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32825
- http://secunia.com/advisories/24501
- http://www.osvdb.org/32772
- http://www.php-security.org/MOPB/BONUS-06-2007.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/22801
- http://www.vupen.com/english/advisories/2007/0829
- http://www.zend.com/products/zend_platform/security_vulnerabilitiesVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32825
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.