CVE-2006-0144

Publication date 9 January 2006

Last updated 17 July 2025


Ubuntu priority

Description

The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.

Status

Package Ubuntu Release Status
php4 7.04 feisty Not in release
6.10 edgy
Not affected
6.06 LTS dapper
Not affected
php5 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected