Lucene search

K
cvelistMitreCVELIST:CVE-2011-1144
HistoryMar 03, 2011 - 12:00 a.m.

CVE-2011-1144

2011-03-0300:00:00
mitre
www.cve.org
5

AI Score

8.9

Confidence

High

EPSS

0

Percentile

15.7%

The installer in PEAR 1.9.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1072.