3.6
CVSSv2

CVE-2014-5459

Published: 27/09/2014 Updated: 29/03/2021
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

The PEAR_REST class in REST.php in PEAR in PHP up to and including 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache functions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php

oracle solaris 11.2

opensuse evergreen 11.4

opensuse opensuse 12.3

opensuse opensuse 13.1

Vendor Advisories

Debian Bug report logs - #682157 [php-pear] "/tmp" symlink file clobbering (CVE-2014-5459) Package: php-pear; Maintainer for php-pear is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Source for php-pear is src:php-pear (PTS, buildd, popcon) Reported by: Laurent Martelli <laurent@bearteamorg> Da ...
The PEAR_REST class in RESTphp in PEAR in PHP through 560 allows local users to write to arbitrary files via a symlink attack on a (1) restcachefile or (2) restcacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache functions ...