PT-2017-4244 · Pear+1 · Pear Base System+1

Hyp3Rlinx

+1

·

Publicado

2017-01-11

·

Atualizado

2022-05-13

·

CVE-2017-5630

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions PEAR Base System version 1.10.1
Description The issue is related to insufficient neutralization of special elements in a request, which can be exploited by a remote attacker to impact data integrity. Specifically, the PECL in the download utility class in the Installer does not validate file types and filenames after a redirect, allowing remote HTTP servers to overwrite files via crafted responses.
Recommendations For PEAR Base System version 1.10.1, consider validating file types and filenames after a redirect to prevent remote HTTP servers from overwriting files. As a temporary workaround, restrict access to the download utility class in the Installer to minimize the risk of exploitation.

Exploit

Correção

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01653
CVE-2017-5630
GHSA-XXV8-PV43-57X5

Produtos afetados

Debian
Pear Base System