CVE-2005-4154

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/12/2005
Last modified:
03/04/2025

Description

Unspecified vulnerability in PEAR installer 1.4.2 and earlier allows user-assisted attackers to execute arbitrary code via a crafted package that can execute code when the pear command is executed or when the Web/Gtk frontend is loaded.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php:pear:*:*:*:*:*:*:*:* 1.4.2 (including)
cpe:2.3:a:php:pear:0.9:*:*:*:*:*:*:*
cpe:2.3:a:php:pear:0.10:*:*:*:*:*:*:*
cpe:2.3:a:php:pear:0.11:*:*:*:*:*:*:*
cpe:2.3:a:php:pear:0.90:*:*:*:*:*:*:*
cpe:2.3:a:php:pear:1.0:*:*:*:*:*:*:*
cpe:2.3:a:php:pear:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:php:pear:1.1:*:*:*:*:*:*:*
cpe:2.3:a:php:pear:1.2:*:*:*:*:*:*:*
cpe:2.3:a:php:pear:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:php:pear:1.3:*:*:*:*:*:*:*
cpe:2.3:a:php:pear:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:php:pear:1.3.3:*:*:*:*:*:*:*
cpe:2.3:a:php:pear:1.3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:php:pear:1.3.4:*:*:*:*:*:*:*