Wednesday, November 23, 2005

Serious vulnerability in the PEAR installer

A poorly-implemented feature allows a package installed by the PEAR installer to execute arbitrary code any time the "pear" command is executed or the Web/Gtk frontend is loaded.

read more | digg story