FAIL › dossier
PEAR
VENDOR· dossier confidence 20%
PEAR, a PHP software component vendor, has faced significant security issues, including high-risk vulnerabilities that led to remote code execution and unauthorized access. These failures have affected multiple healthcare organizations, compromising the data of over 1.26 million patients.
PROFILE
CategoryvendorWhat they doPEAR is a vendor involved in the development and distribution of software components for PHP applications.
Websitehttps://pear.php.net/ ↗
SECURITY POSTURE
The security posture of PEAR has been characterized by high-profile vulnerabilities and breaches, including remote code execution and directory traversal issues.
Notable failures
- CVE-2020-28949
- CVE-2020-36193
Patterns: repeated unpatched vulnerabilities
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-08-25 | CVE-2020-28949 | high | PEAR Archive_Tar untrusted unserialization allowed remote code execution |
| 2022-08-25 | CVE-2020-36193 | high | PEAR's Archive_Tar module exposed directory traversal due to poor symbolic link checking, leading to potential unauthorized access. |
DOSSIER SOURCES
- Mars Inc. - Wikipedia · en.wikipedia.org
- PEAR Ransomware Breach at MCBS Hits 1.26 Million Patients · dailysecurityreview.com
Open questions: What is the current size and ownership of PEAR?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-07 03:42:43.607213+00:00