Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Registered User Nugen's Avatar
    Join Date
    Nov 2005
    Posts
    3

    Default 11-01-2005 | vulnerabilities are reported to affect PHP versions 4.4.0 and prior

    There is a new set of serious security exploits found in PHP. Currently we can only compile 4.4.0. When will 4.4.1 be available via WHM?


    INFO:
    =======================
    http://secunia.com/advisories/16502
    http://www.php.net/release_4_4_1.php
    http://www.hardened-php.net/advisories.15.html
    =======================

    Shout goes out over PHP security bugs
    http://www.theregister.co.uk/2005/11...security_vuln/
    =======================
    Security researchers have identified numerous new vulnerabilities in PHP - the popular, open source web development environment. The critical security flaws create a possible means for hackers to conduct cross-site scripting attacks, bypass certain security restrictions or even (at least potentially) compromise a vulnerable system.

    The vulnerabilities are reported to affect PHP versions 4.4.0 and prior. Users are advised to update to version 4.4.1 (release notes here). Most of this batch of PHP security vulnerabilities (summary) were discovered by Stefan Esser, of the Hardened-PHP Project, which has published a series of advisories here.

    The security bugs described by the Hardened-PHP Project are yet to be developed into s'kiddie friendly exploits. But the past appearance of PHP-targeting worms, and the damage they caused, really ought to prompt the rapid deployment of security updates.

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    v4.4.1 is available in WHM.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  3. #3
    Member
    Join Date
    Jul 2005
    Posts
    74

    Default

    is there any known problem about updating from 4.3.11 to 4.4.1... ? Can it break scripts of my users ?

  4. #4
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    It shouldn't cause problems, but the php developers are notorious in failing to make the app backwards compatible.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

Similar Threads & Tags
Similar threads

  1. Replies: 2
    Last Post: 08-27-2010, 06:45 PM
  2. PHP 5.1.6 / 4.4.4 Critical Vulnerabilities
    By ezztro in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 09-18-2006, 06:14 AM
  3. PHP: Multiple vulnerabilities - Severity: high
    By XPerties in forum cPanel and WHM Discussions
    Replies: 26
    Last Post: 06-07-2006, 12:25 PM
  4. 2 PHP versions 2 mysql versions
    By t9clkclnr in forum Database Discussions
    Replies: 4
    Last Post: 07-07-2005, 11:00 AM
  5. php and vulnerabilities
    By anup123 in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 04-02-2005, 07:26 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube