PEAR packages potentially contain malicious code
Stefan Bethke
stb at lassitu.de
Mon Jan 21 20:19:02 UTC 2019
I’ve just learned that the repository for the PHP PEAR set of extensions had their distribution server compromised.
https://twitter.com/pear/status/1086634503731404800
I don’t really work with PHP much apart from installing packages of popular PHP web apps on my servers, so I can’t tell whether this code made it onto machines building from PEAR sources, or even into FreeBSD binary packages of PEAR extensions. Given the large user base for these packages, some advice to FreeBSD users might be well received.
Thanks,
Stefan
--
Stefan Bethke <stb at lassitu.de> Fon +49 151 14070811
More information about the freebsd-security
mailing list