PT-2017-4244 · Pear+1 · Pear Base System+1

Hyp3Rlinx

+1

·

Published

2017-01-11

·

Updated

2022-05-13

·

CVE-2017-5630

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions PEAR Base System version 1.10.1
Description The issue is related to insufficient neutralization of special elements in a request, which can be exploited by a remote attacker to impact data integrity. Specifically, the PECL in the download utility class in the Installer does not validate file types and filenames after a redirect, allowing remote HTTP servers to overwrite files via crafted responses.
Recommendations For PEAR Base System version 1.10.1, consider validating file types and filenames after a redirect to prevent remote HTTP servers from overwriting files. As a temporary workaround, restrict access to the download utility class in the Installer to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01653
CVE-2017-5630
GHSA-XXV8-PV43-57X5

Affected Products

Debian
Pear Base System