Upstream information
Description
The installer in PEAR before 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories, a different vulnerability than CVE-2007-2519.NVD CVSS v2 Base Score: 3.3 (AV:L/AC:M/Au:N/C:N/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entry: 735613 SUSE Security Advisories:- SUSE-SU-2012:0496-1, published Thu, 12 Apr 2012 23:08:15 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SLE 11 SP1 DEBUGINFO |
| Builds SAT Patch Nr: 5964 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 SUSE Linux Enterprise Software Development Kit 11 SP2 |
| Builds SAT Patch Nr: 5964 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 SUSE Linux Enterprise Software Development Kit 11 SP2 |
| Builds SAT Patch Nr: 5964 |
| SUSE Linux Enterprise Server 11 SP1 SUSE Linux Enterprise Server 11 SP1 for VMware SUSE Linux Enterprise Server 11 SP2 |
| Builds SAT Patch Nr: 5964 |
