mirror of
https://github.com/php/php-src.git
synced 2024-12-01 13:54:10 +08:00
Fix bug #67060: use default mode of 660
This commit is contained in:
parent
4b48b29988
commit
8a22540a95
4
NEWS
4
NEWS
@ -10,6 +10,10 @@ PHP NEWS
|
||||
. Fixed memory corruption in openssl_x509_parse() (CVE-2013-6420).
|
||||
(Stefan Esser).
|
||||
|
||||
- FPM:
|
||||
. Fixed bug #67060 (sapi/fpm: possible privilege escalation due to insecure
|
||||
default configuration) (CVE-2014-0185). (Stas)
|
||||
|
||||
11 Jul 2013, PHP 5.3.27
|
||||
|
||||
- Core:
|
||||
|
@ -35,7 +35,7 @@ int fpm_unix_resolve_socket_premissions(struct fpm_worker_pool_s *wp) /* {{{ */
|
||||
/* uninitialized */
|
||||
wp->socket_uid = -1;
|
||||
wp->socket_gid = -1;
|
||||
wp->socket_mode = 0666;
|
||||
wp->socket_mode = 0660;
|
||||
|
||||
if (!c) {
|
||||
return 0;
|
||||
|
@ -158,10 +158,10 @@ listen = 127.0.0.1:9000
|
||||
; permissions must be set in order to allow connections from a web server. Many
|
||||
; BSD-derived systems allow connections regardless of permissions.
|
||||
; Default Values: user and group are set as the running user
|
||||
; mode is set to 0666
|
||||
; mode is set to 0660
|
||||
;listen.owner = @php_fpm_user@
|
||||
;listen.group = @php_fpm_group@
|
||||
;listen.mode = 0666
|
||||
;listen.mode = 0660
|
||||
|
||||
; List of ipv4 addresses of FastCGI clients which are allowed to connect.
|
||||
; Equivalent to the FCGI_WEB_SERVER_ADDRS environment variable in the original
|
||||
|
Loading…
Reference in New Issue
Block a user