Gentoo Security Advisory GLSA 200603-13 (pear-auth)

Summary
The remote host is missing updates announced in advisory GLSA 200603-13.
Solution
All PEAR-Auth users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose '>=dev-php/PEAR-Auth-1.2.4' http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200603-13 http://bugs.gentoo.org/show_bug.cgi?id=123832
Insight
PEAR-Auth did not correctly verify data passed to the DB and LDAP containers, thus allowing to inject false credentials to bypass the authentication.