Lucene search

K
cve[email protected]CVE-2014-5459
HistorySep 27, 2014 - 10:55 a.m.

CVE-2014-5459

2014-09-2710:55:05
CWE-59
web.nvd.nist.gov
110
php
pear
cve-2014-5459
security
vulnerability
symlink attack
local users
file write
nvd

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.0%

The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache functions.

Affected configurations

NVD
Node
phpphpRange5.6.0
Node
oraclesolarisMatch11.2
Node
opensuseevergreenMatch11.4
OR
opensuseopensuseMatch12.3
OR
opensuseopensuseMatch13.1
CPENameOperatorVersion
php:phpphple5.6.0

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.0%