CVE-2017-5630: PHP PEAR

High severity, CVSS 7.5. EPSS: 12.5% chance of exploitation in the next 30 days.

PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.

Affected products

  • PHP PEAR: version 1.10.1 only

Published 2017-02-01. Last modified 2026-06-17.