CVE-2018-10545
published 2018-04-29CVE-2018-10545: An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing…
PriorityP421medium4.7CVSS 3.0
AVLACHPRLUINSUCHINAN
EPSS
0.83%
53.5th percentile
An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one user (in a multiuser environment) to obtain sensitive information from the process memory of a second user's PHP applications by running gcore on the PID of the PHP-FPM worker process.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| php | php | < 5.6.35 | 5.6.35 |
| php | php | >= 7.0.0 < 7.0.29 | 7.0.29 |
| php | php | >= 7.1.0 < 7.1.16 | 7.1.16 |
| php | php | >= 7.2.0 < 7.2.4 | 7.2.4 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.25 | 5.5.9+dfsg-1ubuntu4.25 |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv4.7MEDIUM
vendor_redhat4.7MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2018-05-16·CVSS 4.7
CVE-2018-10545 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
USN-3646-1 fixed a vulnerability in PHP. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that PHP incorrectly handled opcache access controls
when configured to use PHP-FPM. A local user could possibly use this issue
to obtain sensitive information from another user's PHP applications.
(CVE-2018-10545)
It was discovered that the PHP PHAR error pages incorrectly filtered
certain data. A remote attacker could possibly use this issue to perform
a reflected XSS attack. (CVE-2018-10547)
It was discovered that PHP incorrectly handled LDAP. A malicious remote
LDAP server could possibly use this issue to cause PHP to crash, resulting
in a denial of s
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2018-05-14·CVSS 4.7
CVE-2018-10545 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
It was discovered that PHP incorrectly handled opcache access controls
when configured to use PHP-FPM. A local user could possibly use this issue
to obtain sensitive information from another user's PHP applications.
(CVE-2018-10545)
It was discovered that the PHP iconv stream filter incorrect handled
certain invalid multibyte sequences. A remote attacker could possibly use
this issue to cause PHP to hang, resulting in a denial of service.
(CVE-2018-10546)
It was discovered that the PHP PHAR error pages incorrectly filtered
certain data. A remote attacker could possibly use this issue to perform
a reflected XSS attack. (CVE-2018-10547)
It was discovered that PHP incorrectly handled LDAP. A malicious remote
L
Red Hat
php: Dumpable FPM child processes allow bypassing opcache access controls
vendor_redhat·2017-11-30·CVSS 4.7
CVE-2018-10545 [MEDIUM] CWE-287 php: Dumpable FPM child processes allow bypassing opcache access controls
php: Dumpable FPM child processes allow bypassing opcache access controls
An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one user (in a multiuser environment) to obtain sensitive information from the process memory of a second user's PHP applications by running gcore on the PID of the PHP-FPM worker process.
Statement: Red Hat Product Security has rated this issue as having a security impact of Low, and a future update may address this flaw.
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: php53 (Red Hat Enterprise Linux 5) - Not affected
Package: php (Red Hat Enterprise Li
GHSA
GHSA-67m2-ch47-h5pm: An issue was discovered in PHP before 5
ghsa_unreviewed·2022-05-14
CVE-2018-10545 [MEDIUM] CWE-200 GHSA-67m2-ch47-h5pm: An issue was discovered in PHP before 5
An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one user (in a multiuser environment) to obtain sensitive information from the process memory of a second user's PHP applications by running gcore on the PID of the PHP-FPM worker process.
OSV
php5, php7.0, php7.1, php7.2 vulnerabilities
osv·2018-05-14·CVSS 4.7
CVE-2018-10545 [MEDIUM] php5, php7.0, php7.1, php7.2 vulnerabilities
php5, php7.0, php7.1, php7.2 vulnerabilities
It was discovered that PHP incorrectly handled opcache access controls
when configured to use PHP-FPM. A local user could possibly use this issue
to obtain sensitive information from another user's PHP applications.
(CVE-2018-10545)
It was discovered that the PHP iconv stream filter incorrect handled
certain invalid multibyte sequences. A remote attacker could possibly use
this issue to cause PHP to hang, resulting in a denial of service.
(CVE-2018-10546)
It was discovered that the PHP PHAR error pages incorrectly filtered
certain data. A remote attacker could possibly use this issue to perform
a reflected XSS attack. (CVE-2018-10547)
It was discovered that PHP incorrectly handled LDAP. A malicious remote
LDAP server could possibly use this
OSV
CVE-2018-10545: An issue was discovered in PHP before 5
osv·2018-04-29·CVSS 4.7
CVE-2018-10545 [MEDIUM] CVE-2018-10545: An issue was discovered in PHP before 5
An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one user (in a multiuser environment) to obtain sensitive information from the process memory of a second user's PHP applications by running gcore on the PID of the PHP-FPM worker process.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10545 php: Dumpable FPM child processes allow bypassing opcache access controls
bugzilla·2018-04-04·CVSS 4.7
CVE-2018-10545 [MEDIUM] CVE-2018-10545 php: Dumpable FPM child processes allow bypassing opcache access controls
CVE-2018-10545 php: Dumpable FPM child processes allow bypassing opcache access controls
A flaw was found in PHP versions 5.6 and 7.x. After changing UID and GID, PHP-FPM sets pool worker processes to be dumpable. This allows a local user with the same UID and GID to attach to the PHP-FPM workers and gain access to any restricted resources that are not supposed to be allowed. As a result sensitive configuration data for other accounts can be accessed directly in the PHP worker process's memory.
References:
https://bugs.php.net/bug.php?id=75605
Patch:
https://bugs.php.net/patch-display.php?bug_id=75605&patch=bug75605-patch-for-5-6&revision=latest
https://bugs.php.net/patch-display.php?bug_id=75605&patch=bug75605-patch-for-7-0&revision=latest
Discussion:
Created php tracking bugs for t
Bugzilla
CVE-2018-10545 php: Dumpable FPM child processes allow bypassing opcache access controls [fedora-all]
bugzilla·2018-04-04·CVSS 4.7
CVE-2018-10545 [MEDIUM] CVE-2018-10545 php: Dumpable FPM child processes allow bypassing opcache access controls [fedora-all]
CVE-2018-10545 php: Dumpable FPM child processes allow bypassing opcache access controls [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Trendmicro
Current and Future Attacks Threatening Esports
blogs_trendmicro·2019-10-29
Current and Future Attacks Threatening Esports
Cyber Crime
# Current and Future Attacks Threatening Esports
Cybercriminals will increasingly target the esports industry over the next three years. Many underground forums already have sections dedicated to gaming or esports sales, and the goods and services offered in these forums generate a lot of interest.
By: Mayra Rosario Fuentes, Fernando Merces
2019/10/29
Read time: ( words)
Save to Folio
Esports has evolved from niche entertainment into a highly lucrative industry. Growing ad revenue and sponsorships allow the tournaments to grow; and as the tournaments grow, the prize pool grows as well. Of course, growing popularity and increased funds open up the entities involved to cybercriminals looking for any opportunity to make a profit.
Cheats and hacks are widely available in und
Trendmicro
Current and Future Attacks Threatening Esports
blogs_trendmicro·2019-10-29
Current and Future Attacks Threatening Esports
Cyber Crime
# Current and Future Attacks Threatening Esports
Cybercriminals will increasingly target the esports industry over the next three years. Many underground forums already have sections dedicated to gaming or esports sales, and the goods and services offered in these forums generate a lot of interest.
By: Mayra Rosario Fuentes, Fernando Merces
Oct 29, 2019
Read time: ( words)
Save to Folio
Esports has evolved from niche entertainment into a highly lucrative industry. Growing ad revenue and sponsorships allow the tournaments to grow; and as the tournaments grow, the prize pool grows as well. Of course, growing popularity and increased funds open up the entities involved to cybercriminals looking for any opportunity to make a profit.
Cheats and hacks are widely available in u
http://php.net/ChangeLog-5.phphttp://php.net/ChangeLog-7.phphttp://www.securityfocus.com/bid/104022https://access.redhat.com/errata/RHSA-2019:2519https://bugs.php.net/bug.php?id=75605https://lists.debian.org/debian-lts-announce/2018/05/msg00004.htmlhttps://lists.debian.org/debian-lts-announce/2018/06/msg00005.htmlhttps://security.gentoo.org/glsa/201812-01https://security.netapp.com/advisory/ntap-20180607-0003/https://usn.ubuntu.com/3646-1/https://usn.ubuntu.com/3646-2/https://www.debian.org/security/2018/dsa-4240https://www.tenable.com/security/tns-2018-12http://php.net/ChangeLog-5.phphttp://php.net/ChangeLog-7.phphttp://www.securityfocus.com/bid/104022https://access.redhat.com/errata/RHSA-2019:2519https://bugs.php.net/bug.php?id=75605https://lists.debian.org/debian-lts-announce/2018/05/msg00004.htmlhttps://lists.debian.org/debian-lts-announce/2018/06/msg00005.htmlhttps://security.gentoo.org/glsa/201812-01https://security.netapp.com/advisory/ntap-20180607-0003/https://usn.ubuntu.com/3646-1/https://usn.ubuntu.com/3646-2/https://www.debian.org/security/2018/dsa-4240https://www.tenable.com/security/tns-2018-12
2018-04-29
Published