Release date:
Updated on:
Affected Systems:
PEAR 1.9.1
Unaffected system:
PEAR 1.9.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 46605
Cve id: CVE-2011-1072
PEAR is short for "PHP extensions and application libraries" and is used to provide PHP users with a structured open-source code library.
A security vulnerability exists in the installation program earlier than PEAR 1.9.2. A local attacker can exploit this vulnerability to execute a symbolic link attack, delete or destroy sensitive files, and cause a denial of service.
<* Source: The PHP Group
Link: http://news.php.net/php.pear.cvs/61264
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PEAR
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://pear.php.net/