Symlink Vulnerability in PEAR Installer by PEAR Group
CVE-2011-1072

Currently unrated

Key Information:

Vendor

PHP

Status
Vendor
CVE Published:
3 March 2011

What is CVE-2011-1072?

The PEAR Installer prior to version 1.9.2 contains a vulnerability that enables local users to exploit symlinks to overwrite arbitrary files. This issue is associated with the package.xml file and affects directories such as download_dir, cache_dir, tmp_dir, and pear-build-download. By leveraging this vulnerability, unauthorized users can potentially manipulate critical files, compromising system integrity and security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.