This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

PHP Multiple Vulns - update available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.us-cert.gov/cas/bulletins/SB06-170.html#high

- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-3016
Last revised: 6/14/2006

- http://secunia.com/advisories/19927
Last Update: 2006-05-05
Critical: Moderately critical
Impact: Unknown
Where: From remote
Solution Status: Vendor Patch
Software: PHP 5.1.x …
Description:
Some unspecified vulnerabilities with unknown impacts have been reported in PHP… Many other issues, where some may be security related, have also been reported.
Solution:
Update to version 5.1.4.
http://www.php.net/downloads.php …

EDIT/ADD:
> http://www.php.net/release_5_1_4.php
Last updated: Tue Jun 20 05:20:12 2006 PDT
"…A critical bug with file uploads as well as the fastcgi sapi has been discovered in PHP 5.1.3 and a new PHP release 5.1.4 has been made available to address these two issues. All PHP users are encouraged to upgrade to this release as soon as possible…"

:oops:
FYI…

- http://www.us-cert.gov/cas/bulletins/SB06-248.html#medium

- http://secunia.com/advisories/21546
Last Update: 2006-09-05
Critical: Less critical
Impact: Unknown, Security Bypass
Where: Local system
Solution Status: Vendor Patch…
Description:
Some vulnerabilities have been reported in PHP, where some have unknown impacts, and others can be exploited by malicious, local users to bypass certain security restrictions…
Solution:
Update to version 4.4.4 or 5.1.5.
http://www.php.net/downloads.php …

Original Advisory:
http://www.php.net/release_4_4_4.php
http://www.php.net/release_5_1_5.php …"

.