USN-4654-1: PEAR vulnerabilities
Published Dec 1, 2020
·Updated
It was discovered that PEAR incorrectly sanitized filenames. A remote attacker could possibly use this issue to execute arbitrary code.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/php-pear<1:1.10.9+submodules+notgz-1ubuntu0.20.10.1
1:1.10.9+submodules+notgz-1ubuntu0.20.10.1
Ubuntu Ubuntu=20.10
All of the following
ubuntu/php-pear<1:1.10.9+submodules+notgz-1ubuntu0.20.04.1
1:1.10.9+submodules+notgz-1ubuntu0.20.04.1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/php-pear<1:1.10.5+submodules+notgz-1ubuntu1.18.04.2
1:1.10.5+submodules+notgz-1ubuntu1.18.04.2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/php-pear<1:1.10.1+submodules+notgz-6ubuntu0.2
1:1.10.1+submodules+notgz-6ubuntu0.2
Ubuntu Ubuntu=16.04
Event History
Dec 1, 2020
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-4654-1?
The severity of USN-4654-1 is considered high due to the potential for remote code execution.
2
How do I fix USN-4654-1?
To fix USN-4654-1, you should update the php-pear package to the latest versione as specified in the advisory.
3
Which systems are affected by USN-4654-1?
USN-4654-1 affects Ubuntu versions 16.04, 18.04, 20.04, and 20.10 that have vulnerable php-pear installations.
4
Is there a workaround for USN-4654-1?
There are no recommended workarounds for USN-4654-1; applying the updates is the best course of action.
5
What damages could exploit USN-4654-1 lead to?
Exploiting USN-4654-1 could allow attackers to execute arbitrary code, compromising the security and integrity of the affected systems.