High severity7.5NVD Advisory· Published Feb 1, 2017· Updated May 13, 2026
CVE-2017-5630
CVE-2017-5630
Description
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pear/pearPackagist | <= 1.10.1 | — |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- pear.php.net/bugs/bug.phpnvdVendor AdvisoryWEB
- www.securityfocus.com/bid/95882nvdThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-xxv8-pv43-57x5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-5630ghsaADVISORY
- www.exploit-db.com/exploits/41185/nvdThird Party AdvisoryVDB Entry
- hyp3rlinx.altervista.org/advisories/PEAR-ARBITRARY-FILE-DOWNLOAD.txtghsaWEB
- vimeo.com/201341280ghsaWEB
- web.archive.org/web/20210123222048/https://www.securityfocus.com/bid/95882ghsaWEB
- www.exploit-db.com/exploits/41185ghsaWEB
News mentions
0No linked articles in our index yet.