If you use the popular PEAR PHP extension or have within the last 6 months, there is a possibility that a backdoor could have been introduced depending on how you installed the extension.

"... this does *not* affect the PEAR installer package itself... it affects the go-pear.phar executable that you would use to initially install the PEAR installer. Using the `pear` command to install various PEAR package is *not* affected."

There is still a lot of questions and PEAR PHP are in the process of investigating the full extent of what happened. Please check the references below for the latest updates.


About Us:

RACK911 Labs (HostingSecList) has quickly risen to the top as one of the most respected security firms in the hosting industry. We have already been responsible for finding over 400 new security vulnerabilities in software used by millions and we are on a mission to help secure the internet.

RACK911 Labs
1110 Palms Airport Drive, Suite 110
Las Vegas, NV 89119