Description
sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP YouTube Live Cross-Site Scripting (1.7.21)
WordPress Plugin Contextual Related Posts Cross-Site Request Forgery (2.9.3)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-15110)
WordPress Plugin Are You a Human-The Fun Spam Blocker Cross-Site Scripting (1.4.32)