[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-5459Date: (C)2014-09-13   (M)2023-12-22


The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache functions.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.6
Exploit Score: 3.9
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://www.openwall.com/lists/oss-security/2014/08/27/3
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=759282
openSUSE-SU-2014:1133
openSUSE-SU-2014:1245

CPE    4
cpe:/a:php:php
cpe:/o:opensuse:opensuse:13.1
cpe:/o:opensuse:opensuse:12.3
cpe:/o:oracle:solaris:11.2
...
CWE    1
CWE-59

© SecPod Technologies