CVE-2014-5459
published 2014-09-27CVE-2014-5459: The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2)…
PriorityP416low3.6CVSS 2.0
AVLACLAuNCNIPAP
EPSS
0.64%
46.7th percentile
The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache functions.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opensuse | evergreen | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| php | php | <= 5.6.0 | — |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv3.6LOW
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w8vq-hjwg-7p95: The PEAR_REST class in REST
ghsa_unreviewed·2022-05-13
CVE-2014-5459 [LOW] CWE-59 GHSA-w8vq-hjwg-7p95: The PEAR_REST class in REST
The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache functions.
OSV
CVE-2014-5459: The PEAR_REST class in REST
osv·2014-09-27·CVSS 3.6
CVE-2014-5459 [LOW] CVE-2014-5459: The PEAR_REST class in REST
The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache functions.
Red Hat
php-pear: insecure temporary file use for cache data
vendor_redhat·2014-08-25·CVSS 3.6
CVE-2014-5459 [LOW] CWE-377 php-pear: insecure temporary file use for cache data
php-pear: insecure temporary file use for cache data
The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache functions.
Statement: This issue did not affect the versions of php-pear as shipped with Red Hat Enterprise Linux 5, 6 and 7 as well as Red Hat Software Collections as they do not use a world-writable directory for storing PEAR cache data.
Package: php-pear (Red Hat Enterprise Linux 5) - Not affected
Package: php-pear (Red Hat Enterprise Linux 6) - Not affected
Package: php-pear (Red Hat Enterprise Linux 7) - Not affected
Package: php54-php-pear (Red Hat Software Collections) - Not aff
No detection rules found.
No public exploits indexed.
HackerOne
PHP 5.4.45 is Outdated and Full of Preformance Interupting Arbitrary Code Execution Bugs
hackerone·2017-08-21·CVSS 3.3
CVE-2015-2301 [LOW] PHP 5.4.45 is Outdated and Full of Preformance Interupting Arbitrary Code Execution Bugs
PHP 5.4.45 is Outdated and Full of Preformance Interupting Arbitrary Code Execution Bugs
Your PHP version is affected by quite a few remote arbitrary code execution, remote file renaming, and remote file rewriting bugs that require no authentication and can cause big problems, from performance interruptions and messing with server files to DoS attacks. These are not related to any particular non-default module, but php itself.
Here's a little list I compiled:
CVE-2015-2301
CVE-2014-9652
CVE-2014-5459
CVE-2014-4698
CVE-2014-4670
CVE-2014-3981
Bugzilla
CVE-2014-5459 php-pear: insecure temporary file use for cache data
bugzilla·2014-08-26·CVSS 3.6
CVE-2014-5459 [LOW] CVE-2014-5459 php-pear: insecure temporary file use for cache data
CVE-2014-5459 php-pear: insecure temporary file use for cache data
It was reported that the pear utility insecurely used the /tmp/ directory for cache data. A local attacker could use this flaw to perform a symbolic link attack against a user (typically the root user) running a pear command, causing an arbitrary file to be overwritten, possibly leading to a denial of service.
Original report:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=759282
Discussion:
Created php-pear tracking bugs for this issue:
Affects: fedora-all [bug 1133754]
---
CVE request: http://www.openwall.com/lists/oss-security/2014/08/26/3
---
# pear config-get cache_dir
/var/cache/php-pear
# ll -d /var/cache/php-pear
drwxr-xr-x. 2 root root 147456 22 août 08:57 /var/cache/php-pear
So /tmp is not used wit
http://lists.opensuse.org/opensuse-updates/2014-09/msg00024.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00055.htmlhttp://www.openwall.com/lists/oss-security/2014/08/27/3http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=759282http://lists.opensuse.org/opensuse-updates/2014-09/msg00024.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00055.htmlhttp://www.openwall.com/lists/oss-security/2014/08/27/3http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=759282
2014-09-27
Published