|
|||
|
PHP 4.4.1 has been released
PHP 4.4.1 is now available for download [1]. This version is a maintenance release, that contains numerous bug fixes, including a number of security fixes related to the overwriting of the GLOBALS array. All users of PHP 4.3 and 4.4 are encouraged to upgrade to this version.
Wondering - when it will be in easyapache?
__________________
Regards, Alexei |
|
|||
|
TITLE:
PHP Multiple Vulnerabilities SECUNIA ADVISORY ID: SA17371 VERIFY ADVISORY: http://secunia.com/advisories/17371/ CRITICAL: Moderately critical IMPACT: Security Bypass, Cross Site Scripting, DoS, System access WHERE: >From remote SOFTWARE: PHP 4.0.x http://secunia.com/product/1655/ PHP 4.1.x http://secunia.com/product/1654/ PHP 4.2.x http://secunia.com/product/105/ PHP 4.3.x http://secunia.com/product/922/ PHP 4.4.x http://secunia.com/product/5768/ PHP 5.0.x http://secunia.com/product/3919/ DESCRIPTION: Some vulnerabilities have been reported in PHP, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and potentially compromise a vulnerable system. 1) An error where the "GLOBALS" array is not properly protected, can be exploited to define global variables by sending a "multipart/form-data" POST request with a specially crafted file upload field, or via a script calling the PHP function "extract()" or "import_request_variables()". Successful exploitation may open up for vulnerabilities in various applications, but requires that "register_globals" is enabled. The vulnerability has been reported in versions 4.4.0 and 5.0.5, and prior. 2) An error in the handling of an unexpected termination in the "parse_str()" PHP function, can be exploited to enable the "register_globals" directive for the current execution by e.g. triggering a memory_limit request shutdown in a script calling "parse_str()". The vulnerability has been reported in versions 4.4.0 and 5.0.5, and prior. 3) Some unspecified input passed to the "phpinfo()" PHP function isn't properly sanitised before being returned to the user. This can be exploited via a script calling "phpinfo()" to execute arbitrary HTML and script code in a user's browser session in context of an affected site. The vulnerability has been reported in versions 4.4.0 and 5.0.5, and prior. 4) An integer overflow error in pcrelib may be exploited to cause a memory corruption via a script calling a PHP function using the PCRE library where the regular expression can be controlled by the attacker. For more information: SA16502 Successful exploitation may allow execution of arbitrary code. 5) The problem is that it is possible to bypass the "safe_mode" and "open_basedir" protection mechanisms via the "ext/curl" and "ext/gd" modules. 6) An unspecified error in calling "virtual()" on Apache 2 can be exploited to bypass certain configuration directives (e.g. "safe_mode" and "open_basedir"). Other bugs have also been reported where some may be security related. SOLUTION: Update to version 4.4.1. http://www.php.net/downloads.php |
|
|||
|
__________________
David Mytton - Olate Ltd - mytton.net - UK Dedicated Servers - 99.9% uptime SLA - 15% ionCube Bundle Discount - Simple PHP Bug/Issue Tracking |
|
|||
|
Quote:
http://downloads.zend.com/optimizer/...imizer-2.5.10-.. to http://downloads.zend.com/optimizer/...timizer-2.5.10a-.. |
|
|||
|
Quote:
+1.
__________________
Regards, Alexei |
|
|||
|
this will work with this if u are using linux
http://downloads.zend.com/optimizer/...21-i386.tar.gz |
|
|||
|
Thanks dropby23
What am I meant to do with it though? Do I run the install script from the archive or put it somewhere then run apache update? Sorry for the numpty questions, I'm not used to doing stuff from within WHM. |
![]() |
| Thread Tools | |
| Display Modes | |
|
|