Unspecified vulnerability in PEAR installer 1.4.2 and earlier allows user-assisted attackers to execute arbitrary code via a crafted package that can execute code when the pear command is executed or when the Web/Gtk frontend is loaded.
2005-12-11T02:03:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 5.1 (MEDIUM)
AV:N/AC:H/Au:N/C:P/I:P/A:P
4.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | php | pear | ≤ 1.4.2 | Yes |
Application | php | pear | 0.9 | Yes |
Application | php | pear | 0.10 | Yes |
Application | php | pear | 0.11 | Yes |
Application | php | pear | 0.90 | Yes |
Application | php | pear | 1.0 | Yes |
Application | php | pear | 1.0.1 | Yes |
Application | php | pear | 1.1 | Yes |
Application | php | pear | 1.2 | Yes |
Application | php | pear | 1.2.1 | Yes |
Application | php | pear | 1.3 | Yes |
Application | php | pear | 1.3.1 | Yes |
Application | php | pear | 1.3.3 | Yes |
Application | php | pear | 1.3.3.1 | Yes |
Application | php | pear | 1.3.4 | Yes |
Application | php | pear | 1.3.5 | Yes |
Application | php | pear | 1.3.6 | Yes |
Application | php | pear | 1.4.0 | Yes |
Application | php | pear | 1.4.0 | Yes |
Application | php | pear | 1.4.0 | Yes |
Application | php | pear | 1.4.1 | Yes |