3.3
CVSSv2

CVE-2011-1144

Published: 03/03/2011 Updated: 23/01/2020
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The installer in PEAR 1.9.2 and previous versions allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1072.

Vulnerable Product Search on Vulmon Subscribe to Product

php pear 1.0

php pear 1.0.1

php pear 1.2

php pear 1.3.4

php pear 1.3.3.1

php pear 1.3

php pear 1.4.0

php pear 1.9.1

php pear 1.6.1

php pear 1.5.1

php pear 1.3.6

php pear 1.3.5

php pear

php pear 0.2.2

php pear 0.9

php pear 0.90

php pear 1.2.1

php pear 1.3.3

php pear 1.3.1

php pear 1.4.1

php pear 1.5.0

php pear 0.10

php pear 0.11

php pear 1.1

php pear 1.4.2

Vendor Advisories

Debian Bug report logs - #546164 pear download directory is inherited from the build Package: php-pear; Maintainer for php-pear is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Source for php-pear is src:php-pear (PTS, buildd, popcon) Reported by: Federico Gimenez Nieto <fgimenez@coites> Date: ...
Debian Bug report logs - #618489 CVE-2011-0441: arbitrary files removal via cronjob Package: php5-common; Maintainer for php5-common is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5-common is src:php5 (PTS, buildd, popcon) Reported by: Stephane Chazelas <stephanechazelas@seebytecom> ...
Debian Bug report logs - #581170 php5 crypt() does not complete with emtpy salt Package: php5; Maintainer for php5 is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5 is src:php5 (PTS, buildd, popcon) Reported by: "Raoul Bhatia [IPAX]" <rbhatia@ipaxat> Date: Tue, 11 May 2010 10:33:01 ...
USN 1126-1 introduced two regressions in PHP ...
Multiple vulnerabilities in PHP ...