CVE-2005-4154: Medium severity PHP pear vulnerability
Published Dec 11, 2005
·Updated
Unspecified vulnerability in PEAR installer 1.4.2 and earlier allows user-assisted attackers to execute arbitrary code via a crafted package that can execute code when the pear command is executed or when the Web/Gtk frontend is loaded.
Affected Software
21 affected components
PHP pear=0.9
PHP pear=1.3.4
PHP pear=1.2.1
PHP pear=1.3.3.1
PHP pear=1.0.1
PHP pear=1.0
PHP pear=1.2
PHP pear=1.3
PHP pear=0.90
PHP pear=1.4.0-rc2
PHP pear=1.4.1
PHP pear=1.3.5
PHP pear=1.3.6
PHP pear=1.3.3
PHP pear<=1.4.2
PHP pear=1.3.1
PHP pear=1.4.0-rc1
PHP pear=1.4.0
PHP pear=0.10
PHP pear=0.11
PHP pear=1.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 11, 2005
CVE Published
02:03 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-4154?
CVE-2005-4154 is considered a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2005-4154?
To fix CVE-2005-4154, upgrade your PEAR installation to version 1.4.2 or later.
3
What versions of PEAR are affected by CVE-2005-4154?
CVE-2005-4154 affects PEAR versions up to and including 1.4.1.
4
Can CVE-2005-4154 be exploited remotely?
CVE-2005-4154 is primarily a user-assisted attack, requiring the victim to execute a malicious package.
5
What kind of attacks can be performed using CVE-2005-4154?
CVE-2005-4154 could allow attackers to execute arbitrary code on the user's machine when malicious packages are processed.