CVE-2010-3691: Low severity Apereo Phpcas vulnerability
Published Oct 7, 2010
·Updated
PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to overwrite arbitrary files via a symlink attack on an unspecified file.
Affected Software
30 affected components
Apereo Phpcas=0.2
Apereo Phpcas=0.3
Apereo Phpcas=0.3.1
Apereo Phpcas=0.3.2
Apereo Phpcas=0.4
Apereo Phpcas=0.4.1
Apereo Phpcas=0.4.8
Apereo Phpcas=0.4.9
Apereo Phpcas=0.4.10
Apereo Phpcas=0.4.11
Apereo Phpcas=0.4.12
Apereo Phpcas=0.4.13
Apereo Phpcas=0.4.14
Apereo Phpcas=0.4.15
Apereo Phpcas=0.4.16
Apereo Phpcas=0.4.17
Apereo Phpcas=0.4.18
Apereo Phpcas=0.4.19
Apereo Phpcas=0.4.20
Apereo Phpcas=0.4.21
Apereo Phpcas=0.4.22
Apereo Phpcas=0.4.23
Apereo Phpcas=0.5.0
Apereo Phpcas=0.5.1
Apereo Phpcas=0.6.0
Apereo Phpcas=1.0.0
Apereo Phpcas=1.0.1
Apereo Phpcas=1.1.0
Apereo Phpcas=1.1.1
Apereo Phpcas<=1.1.2
Event History
Oct 7, 2010
CVE Published
via MITRE·08:21 PM
Data Sourced
via MITRE·08:21 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3691?
CVE-2010-3691 has a medium severity level due to its ability to allow local users to overwrite arbitrary files.
2
What versions of phpCAS are affected by CVE-2010-3691?
CVE-2010-3691 affects all versions of phpCAS prior to 1.1.3 when proxy mode is enabled.
3
How do I fix CVE-2010-3691?
To fix CVE-2010-3691, upgrade to phpCAS version 1.1.3 or later, which addresses this vulnerability.
4
What type of attack does CVE-2010-3691 facilitate?
CVE-2010-3691 facilitates a symlink attack that allows local users to overwrite files.
5
Can the impact of CVE-2010-3691 be exploited remotely?
No, the impact of CVE-2010-3691 can only be exploited by local users due to its reliance on local file access.