[AusNOG] Fwd: PEAR PHP Compromised - Possible Backdoor Going Back 6 Months!
noel.butler at ausics.net
Thu Jan 24 16:30:33 EST 2019
This did the rounds of twitter last night, but incase your heads been in
-------- Original Message --------
If you use the popular PEAR PHP extension or have within the last 6
months, there is a possibility that a backdoor could have been
introduced depending on how you installed the extension.
"... this does *not* affect the PEAR installer package itself... it
affects the go-pear.phar executable that you would use to initially
install the PEAR installer. Using the `pear` command to install various
PEAR package is *not* affected."
There is still a lot of questions and PEAR PHP are in the process of
investigating the full extent of what happened. Please check the
references below for the latest updates.
This Email, including any attachments, may contain legally privileged
information, therefore remains confidential and subject to copyright
protected under international law. You may not disseminate, discuss, or
reveal, any part, to anyone, without the authors express written
authority to do so. If you are not the intended recipient, please notify
the sender then delete all copies of this message including attachments,
immediately. Confidentiality, copyright, and legal privilege are not
waived or lost by reason of the mistaken delivery of this message. Only
PDF  and ODF  documents accepted, please do not send proprietary
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the AusNOG