Community Forums
Connect with us on LinkedIn
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 27
  1. #1
    Member java_dude's Avatar
    Join Date
    Apr 2004
    Location
    The Good Ol' U.S. of A.
    Posts
    28

    Default PHP 5.3.10 Released [Case 57077, Case 57160]

    Quote Originally Posted by php.net
    The PHP development team would like to announce the immediate availability of PHP 5.3.10. This release delivers a critical security fix.

    Security Fixes in PHP 5.3.10:
    • Fixed arbitrary remote code execution vulnerability reported by Stefan Esser, CVE-2012-0830.

    All users are strongly encouraged to upgrade to PHP 5.3.10.
    Great, PHP patches 5.3.8 and opens up an even worse security hole in 5.3.9!

  2. #2
    Member
    Join Date
    Feb 2012
    Posts
    14
    cPanel/Enkompass Access Level

    Root Administrator

    Default re: PHP 5.3.10 Released [Case 57077, Case 57160]

    This a critical security fix for PHP. Any idea how long before we'll see it available for an EasyApache build? My server is vulnerable until then.

  3. #3
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default re: PHP 5.3.10 Released [Case 57077, Case 57160]

    We're already aware of this and working on it.

  4. #4
    Registered User
    Join Date
    Jan 2012
    Posts
    1
    cPanel/Enkompass Access Level

    DataCenter Provider

    Default re: PHP 5.3.10 Released [Case 57077, Case 57160]

    Is it too early to ask for an ETA?

  5. #5
    aww
    aww is offline
    Member
    Join Date
    Feb 2005
    Posts
    81
    cPanel/Enkompass Access Level

    Root Administrator

    Default re: PHP 5.3.10 Released [Case 57077, Case 57160]

    Use suhosin as a workaround.

  6. #6
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default re: PHP 5.3.10 Released [Case 57077, Case 57160]

    Quote Originally Posted by getUP View Post
    Is it too early to ask for an ETA?
    I don't have a firm ETA, but I am reasonably confident to say "soon" is a good phrase to use here.

  7. #7
    Member
    Join Date
    Jan 2012
    Posts
    6
    cPanel/Enkompass Access Level

    Root Administrator

    Default re: PHP 5.3.10 Released [Case 57077, Case 57160]

    Quote Originally Posted by aww View Post
    Use suhosin as a workaround.
    does suhosin do it by default or you have to do something to prevent this bug from happening?

  8. #8
    Member
    Join Date
    Feb 2012
    Posts
    14
    cPanel/Enkompass Access Level

    Root Administrator

    Default re: PHP 5.3.10 Released [Case 57077, Case 57160]

    Considering it's late Friday and no word, I am guessing we cannot expect this until Monday at the earliest.

    I don't feel this is acceptable for a critical security flaw that allows arbitrary code execution on my server.

    I have never used Suhosin, don't understand really how it would help in this case, and, as a customer, object to the notion of reconfiguring my server to that extent because cPanel is slow to make the 5.3.10 fix available.

  9. #9
    Member InterServed's Avatar
    Join Date
    Jul 2007
    Posts
    172
    cPanel/Enkompass Access Level

    Root Administrator

    Default re: PHP 5.3.10 Released [Case 57077, Case 57160]

    From my understanding this issue also affects version 5.2.17
    InterServed Tehnologies.
    Affordable web hosting

  10. #10
    Member
    Join Date
    Jan 2012
    Posts
    6
    cPanel/Enkompass Access Level

    Root Administrator

    Default re: PHP 5.3.10 Released [Case 57077, Case 57160]

    Suhosin do block the hash collisions bug in 5.3.8 but i'm not so sure that it block the new bug, that's why im asking, to make sure, since EasyApache as of this time post still does not offer 5.3.10

  11. #11
    Member
    Join Date
    Mar 2008
    Posts
    190

    Default re: PHP 5.3.10 Released [Case 57077, Case 57160]

    Im not sure either why its taking cPanel so much time to fix this, as you can release a patch rather quickly. Even if its breaks something temporary at least you can then take time to properly test that, because between broken and hacked the last time is worst.

    I know DirectAdmin already released a patch yesterday, just a few hours after it was announced. If cPanel really patches this only by Monday it will be a disaster.

    Usually they fix critical security issues very fast.

  12. #12
    Member
    Join Date
    Feb 2012
    Posts
    14
    cPanel/Enkompass Access Level

    Root Administrator

    Default re: PHP 5.3.10 Released [Case 57077, Case 57160]

    Quote Originally Posted by nibb View Post
    I know DirectAdmin already released a patch yesterday, just a few hours after it was announced. If cPanel really patches this only by Monday it will be a disaster.
    I think so too, but it's Saturday morning (PST) and still no update, no further comment.

    Don't want to be a jerk, but I'm prepared to work on this on a Saturday, so I'm expecting the same from cPanel -- We're talking about an arbitrary code execution here.

  13. #13
    Member
    Join Date
    Mar 2008
    Posts
    190

    Default re: PHP 5.3.10 Released [Case 57077, Case 57160]

    Quote Originally Posted by accretor View Post
    I think so too, but it's Saturday morning (PST) and still no update, no further comment.

    Don't want to be a jerk, but I'm prepared to work on this on a Saturday, so I'm expecting the same from cPanel -- We're talking about an arbitrary code execution here.
    I don´t think so. Probably on Monday, or Tuesday.

    I suppose Chinese hackers will have a nice weekend hacking servers.

    This of course will be very bad press for cPanel if thousands of servers happen to appear hacked next week, I guess media is going to be blame this on the late patching of cPanel, because 1 day is ok, but not 4 days or 5 days.

  14. #14
    Member
    Join Date
    Apr 2011
    Location
    US
    Posts
    69
    cPanel/Enkompass Access Level

    Root Administrator

    Default re: PHP 5.3.10 Released [Case 57077, Case 57160]

    It will be available in few days. We just should wait a little.

  15. #15
    aww
    aww is offline
    Member
    Join Date
    Feb 2005
    Posts
    81
    cPanel/Enkompass Access Level

    Root Administrator

    Default re: PHP 5.3.10 Released [Case 57077, Case 57160]

    Quote Originally Posted by Kise S. View Post
    does suhosin do it by default or you have to do something to prevent this bug from happening?
    Suhosin's default is higher than php's so you have to set it lower.

    If you set it lower than php's default of 1000, then the php bug cannot happen (in theory) because the last variable will never make it to php.

    example PHP.ini settings (untested, unproven, just examples and ymmv)
    Code:
    extension="suhosin.so"
    suhosin.memory_limit = 256M
    suhosin.filter.action = 402
    suhosin.cookie.max_array_depth = 64
    suhosin.cookie.max_array_index_length = 256
    suhosin.cookie.max_name_length = 256
    suhosin.cookie.max_totalname_length = 256
    suhosin.cookie.max_value_length = 4096
    suhosin.cookie.max_vars = 256
    suhosin.get.max_array_depth = 64
    suhosin.get.max_array_index_length = 256
    suhosin.get.max_name_length = 256
    suhosin.get.max_totalname_length = 256
    suhosin.get.max_value_length = 4096
    suhosin.get.max_vars = 256
    suhosin.post.max_array_depth = 64
    suhosin.post.max_array_index_length = 256
    suhosin.post.max_name_length = 256
    suhosin.post.max_totalname_length = 256
    suhosin.post.max_value_length = 524288
    suhosin.post.max_vars = 512
    suhosin.request.max_array_depth = 64
    suhosin.request.max_array_index_length = 256
    suhosin.request.max_totalname_length = 256
    suhosin.request.max_value_length = 524288
    suhosin.request.max_vars = 512
    suhosin.request.max_varname_length = 256
    Some of the above are already set higher than the defaults for suhosin and php
    http://www.hardened-php.net/suhosin/configuration.html

    You may need to set them higher if you are running some poorly designed software - but whatever you do, never set it to 1000 or higher, unless your PHP max_input_vars is also higher (always set it less)

    PHP: Runtime Configuration - Manual
    Last edited by aww; 02-05-2012 at 12:58 PM.

Page 1 of 2 1 2 LastLast
Similar Threads & Tags
Similar threads

  1. phpMyAdmin 3.4.7 is released [Case 53974, Case 53975]
    By Ivan A in forum Archived Feature Requests
    Replies: 4
    Last Post: 04-30-2012, 04:34 PM
  2. Replies: 5
    Last Post: 07-29-2011, 09:00 AM
  3. Apache HTTP Server 2.2.19 Released [Case 50042, Case 50053]
    By sparek-3 in forum Archived Feature Requests
    Replies: 8
    Last Post: 05-26-2011, 02:20 PM
  4. Replies: 8
    Last Post: 03-20-2011, 07:37 PM
  5. [Case 45931, Case 45932] PHP 5.3.5 and 5.2.17 Released
    By Ivan A in forum Archived Feature Requests
    Replies: 20
    Last Post: 03-07-2011, 01:58 PM
Tags for this Thread
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube