FYI…

- http://www.php.net/release_4_4_1.php
The PHP Development Team would like to announce the immediate release of PHP 4.4.1. This is a bug fix release, which addresses some security problems too… This release also fixes 35 other defects, where the most important is the the fix that removes a notice when passing a by-reference result of a function as a by-reference value to another function…"
- http://www.php.net/ChangeLog-4.php#4.4.1
Version 4.4.1
31-Oct-2005

- http://secunia.com/advisories/17371/
"…Release Date: 2005-10-31
Critical: Moderately critical
Impact: Security Bypass, Cross Site Scripting, DoS, system access
Where: From remote
Solution Status: Vendor Patch
Software: PHP 4.0.x, PHP 4.1.x, PHP 4.2.x, PHP 4.3.x. PHP 4.4.x, PHP 5.0.x
CVE reference: CAN-2005-2491
Description:
Some vulnerabilities have been reported in PHP, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and potentially compromise a vulnerable system…
Solution: Update to version 4.4.1.
http://www.php.net/downloads.php …"

:ph34r: