Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #17868
| From | "!!Memphis!!" <betareq@microsoft.com> |
|---|---|
| Newsgroups | comp.lang.php, alt.comp.lang.php, alt.php, comp.programming, comp.security.misc, alt.privacy.spyware, alt.virus, alt.anti-virus, comp.security.unix |
| Subject | Security breach for PHP's popular pear.php.net site |
| Followup-To | alt.privacy.spyware, comp.lang.php, comp.security.misc |
| Date | 2019-01-26 04:34 +0000 |
| Organization | Neodome |
| Message-ID | <q2go0n$j8o$1@neodome.net> (permalink) |
Cross-posted to 9 groups.
Followups directed to: alt.privacy.spyware, comp.lang.php, comp.security.misc
<https://www.bleepingcomputer.com/forums/t/690215/security-breach-for-phps-popular-pearphpnet-site/> Posted 21 January 2019 - 10:40 PM The twitter feed for the PHP Extension and Application Repository (PEAR) reported on January 19 that there was a security breach. They additionally indicate that those that have downloaded go-pear.phar in the last six months should get a new copy from github. The tweets are here: https://twitter.com/pear/status/1086634389465956352 https://twitter.com/pear/status/1086634503731404800 The home page for php.net currently doesn't indicate anything. Last update for the PHP.net was January 10th regarding the release of PHP versions 5.6.40, 7.1.26, 7.2.14 and 7.3.1. PEAR is used by several PHP users and a popular source for installing PHP code that other PHP applications depend on. The PEAR installer does include an optional GPG digital signing but this does not seem to be popularly used or mandated for inclusion on the PEAR hosting site.
Back to comp.lang.php | Previous | Next — Next in thread | Find similar | Unroll thread
Security breach for PHP's popular pear.php.net site "!!Memphis!!" <betareq@microsoft.com> - 2019-01-26 04:34 +0000 Re: Security breach for PHP's popular pear.php.net site Mi Na <ya12983@mail.com> - 2021-07-23 00:50 -0700
csiph-web