| ID | CVE-2011-1144 | ||||||
| Sažetak | The installer in PEAR 1.9.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1072. | ||||||
| Reference |
|
||||||
| CVSS |
|
||||||
| Pristup |
|
||||||
| Impact |
|
||||||
| CVSS vektor | AV:L/AC:M/Au:N/C:N/I:P/A:P | ||||||
| Zadnje važnije ažuriranje | 23-01-2020 - 14:33 | ||||||
| Objavljeno | 03-03-2011 - 01:00 |

