Welcome to P2PNET.net - The original daily p2p and digital news site. Always First!
Register | Login
RIAA News
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
TV
Open Source
Mobiles
Advertising
Product News
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Search: 
Search
 
Web P2PNET   
Search: 
Search
Torrent Site Tracker
MP3rocket
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code
p2pnet - rss feed: http://p2pnet.net/p2p.rss | p2pnet celebrities: http://p2pnet.net/celeb.rss | Mobile? http://p2pnet.net/index-wml.php

‘Critical’ PHP vulnerabilities

p2pnet.net News:- Hardened-PHP says multiple critical vulnerabilities that allow local and remote execution of arbitrary code have been found in PHP 4 / 5.

“During the development of Hardened-PHP which adds security hardening features to the PHP codebase, several vulnerabilities within PHP were discovered that reach from bufferoverflows, over information leak vulnerabilities and path truncation vulnerabilities to safe_mode restriction bypass vulnerabilities,” it says.

Vulnerable scripts include:

  • phpBB2
  • Invision Board
  • vBulletin
  • Woltlab Burning Board 2.x
  • Serendipity Weblog
  • phpAds(New)

However, the just-released v0.2.4 backports several security fixes that went into PHP 4.3.10, and also has a few new features, says the site, adding:

“Most probably it will be the last release in the 0.2.x series because the 0.3.x tree is currently in a closed beta test.”

Hardened-PHP “strongly recommends” upgrading to the new PHP-Releases a soon as possible, “because a lot of PHP applications expose the easy to exploit unserialize() vulnerability to remote attackers. Additionally we always recommend to run PHP with the Hardened-PHP patch applied.”

Hardened-PHP says it won’t be releasing vulnerability exploits to the public.

===================

See:-
critical vulnerabilities - Multiple vulnerabilities within PHP 4/5, Hardened-PHP, December 15, 2004

HOME

One Response to “‘Critical’ PHP vulnerabilities”

  1. Reader's Write Says:

    yawn

Leave a Reply

    Advertisments
Teksavvy