CVE-2013-5724: Low severity phpbb vulnerability
Published Sep 11, 2013
·Updated
Phpbb3 before 3.0.11-4 for Debian GNU/Linux uses world-writable permissions for cache files, which allows local users to modify the file contents via standard filesystem write operations.
Affected Software
26 affected components
Debian Phpbb3<=3.0.11-3
Debian Phpbb3=3.0.0-1
Debian Phpbb3=3.0.0-2
Debian Phpbb3=3.0.0-b5
Debian Phpbb3=3.0.0-rc1
Debian Phpbb3=3.0.0-rc2-1
Debian Phpbb3=3.0.0-rc3-1
Debian Phpbb3=3.0.0-rc4-1
Debian Phpbb3=3.0.0-rc5-1
Debian Phpbb3=3.0.0-rc7-1
Debian Phpbb3=3.0.1-1
Debian Phpbb3=3.0.2-1
Debian Phpbb3=3.0.2-2
Debian Phpbb3=3.0.2-3
Debian Phpbb3=3.0.2-4
Debian Phpbb3=3.0.4-1
Debian Phpbb3=3.0.7-p1-1
Debian Phpbb3=3.0.7-p1-2
Debian Phpbb3=3.0.7-p1-3
Debian Phpbb3=3.0.7-p1-4
Debian Phpbb3=3.0.7-p1-5
Debian Phpbb3=3.0.9-1
Debian Phpbb3=3.0.10-1
Debian Phpbb3=3.0.10-2
Debian Phpbb3=3.0.11-1
Debian Phpbb3=3.0.11-2
Event History
Sep 11, 2013
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5724?
CVE-2013-5724 has a moderate severity rating due to its potential to allow local users to alter cache file contents.
2
How do I fix CVE-2013-5724?
To fix CVE-2013-5724, update phpBB3 to version 3.0.11-4 or later to ensure proper file permissions.
3
Who is affected by CVE-2013-5724?
CVE-2013-5724 affects all versions of phpBB3 prior to 3.0.11-4 installed on Debian GNU/Linux.
4
What access does CVE-2013-5724 grant to local users?
CVE-2013-5724 allows local users to modify the contents of world-writable cache files.
5
What steps can be taken to prevent CVE-2013-5724 exploitation?
Prevent exploitation of CVE-2013-5724 by enforcing strict file permissions and regularly updating software.