CVE-2010-3691

PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to overwrite arbitrary files via a symlink attack on an unspecified file.
References
Link Resource
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495542#82
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050415.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050428.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049600.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049602.html
http://secunia.com/advisories/41878
http://secunia.com/advisories/42149
http://secunia.com/advisories/42184
http://secunia.com/advisories/43427
http://www.debian.org/security/2011/dsa-2172
http://www.openwall.com/lists/oss-security/2010/09/29/6
http://www.openwall.com/lists/oss-security/2010/10/01/2
http://www.openwall.com/lists/oss-security/2010/10/01/5
http://www.securityfocus.com/bid/43585
http://www.vupen.com/english/advisories/2010/2705
http://www.vupen.com/english/advisories/2010/2909
http://www.vupen.com/english/advisories/2011/0456
https://developer.jasig.org/source/changelog/jasigsvn?cs=21538
https://forge.indepnet.net/projects/glpi/repository/revisions/12601
https://issues.jasig.org/browse/PHPCAS-80
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495542#82
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050415.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050428.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049600.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049602.html
http://secunia.com/advisories/41878
http://secunia.com/advisories/42149
http://secunia.com/advisories/42184
http://secunia.com/advisories/43427
http://www.debian.org/security/2011/dsa-2172
http://www.openwall.com/lists/oss-security/2010/09/29/6
http://www.openwall.com/lists/oss-security/2010/10/01/2
http://www.openwall.com/lists/oss-security/2010/10/01/5
http://www.securityfocus.com/bid/43585
http://www.vupen.com/english/advisories/2010/2705
http://www.vupen.com/english/advisories/2010/2909
http://www.vupen.com/english/advisories/2011/0456
https://developer.jasig.org/source/changelog/jasigsvn?cs=21538
https://forge.indepnet.net/projects/glpi/repository/revisions/12601
https://issues.jasig.org/browse/PHPCAS-80
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apereo:phpcas:*:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.2:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.3:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.3.2:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.1:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.8:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.9:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.10:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.11:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.12:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.13:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.14:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.15:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.16:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.17:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.18:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.19:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.20:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.21:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.22:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.4.23:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.5.0:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.5.1:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:0.6.0:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apereo:phpcas:1.1.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:19

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495542#82 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495542#82 -
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050415.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050415.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050428.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050428.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049600.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049600.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049602.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049602.html -
References () http://secunia.com/advisories/41878 - () http://secunia.com/advisories/41878 -
References () http://secunia.com/advisories/42149 - () http://secunia.com/advisories/42149 -
References () http://secunia.com/advisories/42184 - () http://secunia.com/advisories/42184 -
References () http://secunia.com/advisories/43427 - () http://secunia.com/advisories/43427 -
References () http://www.debian.org/security/2011/dsa-2172 - () http://www.debian.org/security/2011/dsa-2172 -
References () http://www.openwall.com/lists/oss-security/2010/09/29/6 - () http://www.openwall.com/lists/oss-security/2010/09/29/6 -
References () http://www.openwall.com/lists/oss-security/2010/10/01/2 - () http://www.openwall.com/lists/oss-security/2010/10/01/2 -
References () http://www.openwall.com/lists/oss-security/2010/10/01/5 - () http://www.openwall.com/lists/oss-security/2010/10/01/5 -
References () http://www.securityfocus.com/bid/43585 - () http://www.securityfocus.com/bid/43585 -
References () http://www.vupen.com/english/advisories/2010/2705 - () http://www.vupen.com/english/advisories/2010/2705 -
References () http://www.vupen.com/english/advisories/2010/2909 - () http://www.vupen.com/english/advisories/2010/2909 -
References () http://www.vupen.com/english/advisories/2011/0456 - () http://www.vupen.com/english/advisories/2011/0456 -
References () https://developer.jasig.org/source/changelog/jasigsvn?cs=21538 - () https://developer.jasig.org/source/changelog/jasigsvn?cs=21538 -
References () https://forge.indepnet.net/projects/glpi/repository/revisions/12601 - () https://forge.indepnet.net/projects/glpi/repository/revisions/12601 -
References () https://issues.jasig.org/browse/PHPCAS-80 - () https://issues.jasig.org/browse/PHPCAS-80 -

Information

Published : 2010-10-07 21:00

Updated : 2024-11-21 01:19


NVD link : CVE-2010-3691

Mitre link : CVE-2010-3691

CVE.ORG link : CVE-2010-3691


JSON object : View

Products Affected

apereo

  • phpcas
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')