CVE Vulnerabilities

CVE-2007-2519

Published: May 22, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the (1) install-as attribute in the file element in package.xml 1.0 or the (2) as attribute in the install element in package.xml 2.0. NOTE: it could be argued that this does not cross privilege boundaries in typical installations, since the code being installed could perform the same actions.

Affected Software

NameVendorStart VersionEnd Version
PearPhp_group1.0 (including)1.0 (including)
PearPhp_group1.0.1 (including)1.0.1 (including)
PearPhp_group1.1 (including)1.1 (including)
PearPhp_group1.2 (including)1.2 (including)
PearPhp_group1.2.1 (including)1.2.1 (including)
PearPhp_group1.2b1 (including)1.2b1 (including)
PearPhp_group1.2b2 (including)1.2b2 (including)
PearPhp_group1.2b3 (including)1.2b3 (including)
PearPhp_group1.2b4 (including)1.2b4 (including)
PearPhp_group1.2b5 (including)1.2b5 (including)
PearPhp_group1.3 (including)1.3 (including)
PearPhp_group1.3.1 (including)1.3.1 (including)
PearPhp_group1.3.3 (including)1.3.3 (including)
PearPhp_group1.3.3.1 (including)1.3.3.1 (including)
PearPhp_group1.3.4 (including)1.3.4 (including)
PearPhp_group1.3.5 (including)1.3.5 (including)
PearPhp_group1.3.6 (including)1.3.6 (including)
PearPhp_group1.3b1 (including)1.3b1 (including)
PearPhp_group1.3b2 (including)1.3b2 (including)
PearPhp_group1.3b3 (including)1.3b3 (including)
PearPhp_group1.3b5 (including)1.3b5 (including)
PearPhp_group1.3b6 (including)1.3b6 (including)
PearPhp_group1.4.0 (including)1.4.0 (including)
PearPhp_group1.4.0a1 (including)1.4.0a1 (including)
PearPhp_group1.4.0a2 (including)1.4.0a2 (including)
PearPhp_group1.4.0a3 (including)1.4.0a3 (including)
PearPhp_group1.4.0a4 (including)1.4.0a4 (including)
PearPhp_group1.4.0a5 (including)1.4.0a5 (including)
PearPhp_group1.4.0a6 (including)1.4.0a6 (including)
PearPhp_group1.4.0a7 (including)1.4.0a7 (including)
PearPhp_group1.4.0a8 (including)1.4.0a8 (including)
PearPhp_group1.4.0a9 (including)1.4.0a9 (including)
PearPhp_group1.4.0a10 (including)1.4.0a10 (including)
PearPhp_group1.4.0a11 (including)1.4.0a11 (including)
PearPhp_group1.4.0a12 (including)1.4.0a12 (including)
PearPhp_group1.4.0b1 (including)1.4.0b1 (including)
PearPhp_group1.4.0b2 (including)1.4.0b2 (including)
PearPhp_group1.4.0rc1 (including)1.4.0rc1 (including)
PearPhp_group1.4.0rc2 (including)1.4.0rc2 (including)
PearPhp_group1.4.1 (including)1.4.1 (including)
PearPhp_group1.4.2 (including)1.4.2 (including)
PearPhp_group1.4.3 (including)1.4.3 (including)
PearPhp_group1.4.4 (including)1.4.4 (including)
PearPhp_group1.4.5 (including)1.4.5 (including)
PearPhp_group1.4.6 (including)1.4.6 (including)
PearPhp_group1.4.7 (including)1.4.7 (including)
PearPhp_group1.4.8 (including)1.4.8 (including)
PearPhp_group1.4.9 (including)1.4.9 (including)
PearPhp_group1.4.10 (including)1.4.10 (including)
PearPhp_group1.4.10rc1 (including)1.4.10rc1 (including)
PearPhp_group1.4.11 (including)1.4.11 (including)
PearPhp_group1.5.0 (including)1.5.0 (including)
PearPhp_group1.5.0a1 (including)1.5.0a1 (including)
PearPhp_group1.5.0rc1 (including)1.5.0rc1 (including)
PearPhp_group1.5.0rc2 (including)1.5.0rc2 (including)
PearPhp_group1.5.0rc3 (including)1.5.0rc3 (including)
PearPhp_group1.5.1 (including)1.5.1 (including)
PearPhp_group1.5.2 (including)1.5.2 (including)
PearPhp_group1.5.3 (including)1.5.3 (including)
Php5Ubuntudapper*
Php5Ubuntuedgy*
Php5Ubuntufeisty*
Php5Ubuntuupstream*

References