Cyberanswers is now on youtube

Register a free account
ne nw
Crawlability Inc. Files for SEO Technology Patent
se sw

Go Back   Forum Index > Operating Systems > Linux
The Software Store

Linux All distros and thier applications

Reply
 
Thread Tools Display Modes
  #1  
Old 06-04-2007, 11:08 PM
Mandriva's Avatar
Mandriva Mandriva is offline
Senior Member
 
Join Date: Oct 2006
Posts: 720
Mandriva- Advisories MDKSA-2007:110: Updated php-pear packages fix directory traversal vulnerability

Advisories MDKSA-2007:110: Updated php-pear packages fix directory traversal vulnerability
A security hole was discovered in all versions of the PEAR Installer
(http://pear.php.net/PEAR). The security hole is the most serious
hole found to date in the PEAR Installer, and would allow a malicious
package to install files anywhere in the filesystem.

The vulnerability only affects users who are installing an
intentionally created package with a malicious intent. Because the
package is easily traced to its source, this is most likely to happen
if a hacker were to compromise a PEAR channel server and alter a
package to install a backdoor. In other words, it must be combined
with other exploits to be a problem.

Updated packages have been patched to prevent this issue.
http://mandrivausers.org/index.php?showtopic=41935
Array
Mon, 04 Jun 2007 22:58:32 +0000
Reply With Quote
Sponsored Links

Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump


All times are GMT -5. The time now is 08:35 AM.


234x60
Bulletin Board Custom Version by Mobo
Copyright © 2004-2007 Cyberanswers.org All rights reserved