CVE-2007-1369: Medium severity Zend Zend Platform vulnerability
Published Mar 9, 2007
·Updated
inimodifier (sgid-zendtech) in Zend Platform 2.2.3 and earlier allows local users to modify the system php.ini file by editing a copy of php.ini file using the -f parameter, and then performing a symlink attack using the directory that contains the attacker-controlled php.ini file, and linking this directory to /usr/local/Zend/etc.
Affected Software
1 affected component
Zend Zend Platform<=2.2.3
Remediation
Event History
Mar 9, 2007
CVE Published
10:19 PM
Mar 10, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1369?
CVE-2007-1369 has a medium severity level due to its local exploitation potential.
2
How do I fix CVE-2007-1369?
To fix CVE-2007-1369, upgrade to a version of Zend Platform later than 2.2.3.
3
Who is affected by CVE-2007-1369?
CVE-2007-1369 affects users running Zend Platform version 2.2.3 and earlier.
4
What are the potential impacts of CVE-2007-1369?
The potential impacts of CVE-2007-1369 include unauthorized modification of sensitive php.ini configurations.
5
What type of attack does CVE-2007-1369 exploit?
CVE-2007-1369 exploits a symlink attack to compromise the php.ini file.