3.3
CVSSv2

CVE-2011-1072

Published: 03/03/2011 Updated: 23/01/2020
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The installer in PEAR prior to 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories, a different vulnerability than CVE-2007-2519.

Vulnerable Product Search on Vulmon Subscribe to Product

php pear 0.11

php pear 1.0

php pear 1.2

php pear 1.3.6

php pear 1.3.5

php pear 1.4.0

php pear 0.90

php pear 0.10

php pear 1.2.1

php pear 1.1

php pear 1.3

php pear 1.4.2

php pear 0.2.2

php pear 0.9

php pear 1.0.1

php pear 1.3.3

php pear 1.3.1

php pear 1.4.1

php pear

php pear 1.6.1

php pear 1.3.4

php pear 1.3.3.1

php pear 1.5.1

php pear 1.5.0

Vendor Advisories

Synopsis Low: php-pear security and bug fix update Type/Severity Security Advisory: Low Topic An updated php-pear package that fixes one security issue and multiple bugsis now available for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having lowsecurity impact A Co ...
Debian Bug report logs - #546164 pear download directory is inherited from the build Package: php-pear; Maintainer for php-pear is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Source for php-pear is src:php-pear (PTS, buildd, popcon) Reported by: Federico Gimenez Nieto <fgimenez@coites> Date: ...
Debian Bug report logs - #618489 CVE-2011-0441: arbitrary files removal via cronjob Package: php5-common; Maintainer for php5-common is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5-common is src:php5 (PTS, buildd, popcon) Reported by: Stephane Chazelas <stephanechazelas@seebytecom> ...
Debian Bug report logs - #581170 php5 crypt() does not complete with emtpy salt Package: php5; Maintainer for php5 is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5 is src:php5 (PTS, buildd, popcon) Reported by: "Raoul Bhatia [IPAX]" <rbhatia@ipaxat> Date: Tue, 11 May 2010 10:33:01 ...
Several vulnerabilities have been discovered in PHP, the web scripting language The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2011-1072 It was discovered that insecure handling of temporary files in the PEAR installer could lead to denial of service CVE-2011-4153 Maksymilian Arciemowicz discovered ...
USN 1126-1 introduced two regressions in PHP ...
Multiple vulnerabilities in PHP ...