PEAR Archive_Tar versions prior to 1.4.4 suffers from a php object injection vulnerability.
301d1addd2f16d82750f17ee54102420
Debian Linux Security Advisory 4378-1 - Fariskhi Vidyan discovered that the PEAR Archive_Tar package for handling tar files in PHP is prone to a PHP object injection vulnerability, potentially allowing a remote attacker to execute arbitrary code.
eaa1c640aaefdbb4400c736c327d0918
Ubuntu Security Notice 3857-1 - Fariskhi Vidyan discovered that PEAR Archive_Tar incorrectly handled certain archive paths. A remote attacker could possibly use this issue to execute arbitrary code.
0216917c7cb3ac850f31adf9b107774b
Secunia Security Advisory - Hamid Ebadi has discovered a vulnerability in PEAR Archive_Tar, which potentially can be exploited by malicious people to compromise a user's system.
2dc0b022b0f8b471f00c8b4380c63029