This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

PHP 5.2.1 released

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.html?storyid=2202
Last Updated: 2007-02-09 09:41:44 UTC ~ "PHP.net* released their version 5.2.1** which contains a number of security fixes.
"The majority of the security vulnerabilities discovered and resolved can in most cases be only abused by local users and cannot be triggered remotely. However, some of the above issues can be triggered remotely in certain situations, or exploited by malicious local users on shared hosting setups utilizing PHP as an Apache module. Therefore, we strongly advise all users of PHP, regardless of the version to upgrade to 5.2.1 release as soon as possible. PHP 4.4.5 with equivalent security corrections will be available shortly."

* http://www.php.net/

** http://www.php.net/releases/5_2_1.php

.
FYI…

- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0905
Original release date: 2/13/2007
Source: US-CERT/NIST
"PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension. NOTE: it is possible that this issue is a duplicate of CVE-2006-6383*…"
* http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6383

- http://secunia.com/advisories/24089
Release Date: 2007-02-09
Critical: Moderately critical
Impact: Unknown, Security Bypass, Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch
Software: PHP 5.1.x, PHP 5.2.x
…Other issues which may be security related have also been reported.
NOTE: Some issues can be triggered remotely under certain circumstances.
Solution: Update to version 5.2.1…"

:ph34r: