File tree Expand file tree Collapse file tree 3 files changed +5
-3
lines changed Expand file tree Collapse file tree 3 files changed +5
-3
lines changed Original file line number Diff line number Diff line change @@ -45,6 +45,8 @@ PHP NEWS
45
45
. Fixed bug #66482 (unknown entry 'priority' in php-fpm.conf).
46
46
. Fixed bug #66908 (php-fpm reload leaks epoll_create() file descriptor).
47
47
(Julio Pintos)
48
+ . Fixed bug #67060 (sapi/fpm: possible privilege escalation due to insecure
49
+ default configuration) (CVE-2014-0185). (Stas)
48
50
49
51
- GMP:
50
52
. Fixed crashes in serialize/unserialize. (Stas)
Original file line number Diff line number Diff line change @@ -39,7 +39,7 @@ int fpm_unix_resolve_socket_premissions(struct fpm_worker_pool_s *wp) /* {{{ */
39
39
/* uninitialized */
40
40
wp -> socket_uid = -1 ;
41
41
wp -> socket_gid = -1 ;
42
- wp -> socket_mode = 0666 ;
42
+ wp -> socket_mode = 0660 ;
43
43
44
44
if (!c ) {
45
45
return 0 ;
Original file line number Diff line number Diff line change @@ -166,10 +166,10 @@ listen = 127.0.0.1:9000
166
166
; permissions must be set in order to allow connections from a web server. Many
167
167
; BSD-derived systems allow connections regardless of permissions.
168
168
; Default Values: user and group are set as the running user
169
- ; mode is set to 0666
169
+ ; mode is set to 0660
170
170
;listen.owner = @php_fpm_user@
171
171
;listen.group = @php_fpm_group@
172
- ;listen.mode = 0666
172
+ ;listen.mode = 0660
173
173
174
174
; List of ipv4 addresses of FastCGI clients which are allowed to connect.
175
175
; Equivalent to the FCGI_WEB_SERVER_ADDRS environment variable in the original
You can’t perform that action at this time.
0 commit comments