CVE-2007-1370: Medium severity Zend Zend Platform vulnerability
Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modifying the files. NOTE: this only occurs when safemode and openbasedir are disabled; other settings require leverage for other vulnerabilities.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1370?
CVE-2007-1370 is considered a critical vulnerability due to its potential to allow local users to gain root privileges.
How do I fix CVE-2007-1370?
To fix CVE-2007-1370, ensure that safe_mode and open_basedir are enabled and restrict file permissions on affected files.
What are the affected versions in CVE-2007-1370?
CVE-2007-1370 affects Zend Platform versions 2.2.3 and earlier.
Can CVE-2007-1370 be exploited remotely?
CVE-2007-1370 requires local access to exploit, so it cannot be exploited remotely.
Is CVE-2007-1370 fixed in newer versions of Zend Platform?
Yes, newer versions of Zend Platform have addressed the vulnerabilities identified in CVE-2007-1370.