Описание
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.
A vulnerability was found in php-pear where if a malicious server responded to a pear
Отчет
Since pear's purpose is to download libraries for inclusion in an application, any use of pear install
or pear download
implicitly trusts the server. This vulnerability does not significantly extend the trust already given to pear and to servers used with it.
Меры по смягчению последствий
This vulnerability only allows files in the current directory to be overwritten, so using pear download
in a temporary directory effectively mitigates the risk of a dangerous file overwrite occurring.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | php-pear | Will not fix | ||
Red Hat Enterprise Linux 6 | php-pear | Will not fix | ||
Red Hat Enterprise Linux 7 | php-pear | Will not fix | ||
Red Hat Software Collections | rh-php56-php-pear | Will not fix | ||
Red Hat Software Collections | rh-php70-php-pear | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
3.4 Low
CVSS3
Связанные уязвимости
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.
PECL in the download utility class in the Installer in PEAR Base Syste ...
Уязвимость библиотеки классов PHP PEAR, связанная с недостаточной нейтрализацией специальных элементов в запросе, позволяющая нарушителю оказать воздействие на целостность данных
EPSS
3.4 Low
CVSS3