PublicDateAtUSN: 2011-03-02 Candidate: CVE-2011-1144 PublicDate: 2011-03-03 01:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1144 http://openwall.com/lists/oss-security/2011/03/01/9 https://ubuntu.com/security/notices/USN-1126-1 Description: The installer in PEAR 1.9.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1072. Ubuntu-Description: Notes: kees> php5 5.3.5 still contains a vulnerable version: kees> $ grep version /usr/share/php/PEAR.php | tail -n1 kees> * @version Release: 1.9.1 Bugs: Priority: low Discovered-by: Dan Rosenberg Assigned-to: sbeattie CVSS: Patches_php5: upstream: http://svn.php.net/viewvc?view=revision&revision=309042 upstream_php5: needs-triage dapper_php5: released (5.1.2-1ubuntu3.22) hardy_php5: released (5.2.4-2ubuntu5.15) karmic_php5: released (5.2.10.dfsg.1-2ubuntu6.9) lucid_php5: released (5.3.2-1ubuntu4.8) maverick_php5: released (5.3.3-1ubuntu9.4) natty_php5: released (5.3.5-1ubuntu7.1) devel_php5: not-affected (5.3.5-1ubuntu7.2)