File Overwrite Vulnerability in PEAR Installer by PECL
CVE-2017-5630

7.5HIGH

Key Information:

Vendor

PHP

Status
Vendor
CVE Published:
1 February 2017

What is CVE-2017-5630?

A security flaw exists in the PECL download utility class within the PEAR Base System version 1.10.1, where it fails to properly validate file types and filenames after a redirect. This oversight creates a potential risk that allows remote HTTP servers to exploit the utility, enabling them to overwrite files on the server by sending specially crafted responses. Attackers could leverage this vulnerability to alter important configuration files, such as .htaccess, leading to further security risks.

References

EPSS Score

7% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.