<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Sun, 07 Sep 2008 16:19:43 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[Community News: Avaya Products PHP Multiple Vulnerabilities]]></title>
      <guid>http://www.phpdeveloper.org/news/8977</guid>
      <link>http://www.phpdeveloper.org/news/8977</link>
      <description><![CDATA[<p>
As mentioned in <a href="http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm">this new security advisory</a> from Avaya, there's a risk that the PHP version included with their Messaging systems could provide a hole for a would-be attacker to gain access.
</p>
<p>
Issues have been reported in the following:
</p>
<ul>
<li>integer overflow vulnerabilities in the PHP gd extension
<li>integer overflow vulnerability in the PHP chunk_split function
<li>a security update has introduced a bug into PHP session cookie handling
<li>vulnerability in the PHP money_format function
<li>vulnerability in the PHP wordwrap function
<li>vulnerability in PHP session cookie handling
<li>vulnerability in the PHP gc extension
</ul>
<p>
The <a href="http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm">advisory</a> contains links to more information from RedHat on these issues and includes a list of systems effected as well as recommended actions to take. 
</p>]]></description>
      <pubDate>Tue, 06 Nov 2007 07:56:00 -0600</pubDate>
    </item>
    <item>
      <title><![CDATA[Advisory: Gentoo Linux PHP Package Upgrade]]></title>
      <guid>http://www.phpdeveloper.org/news/8798</guid>
      <link>http://www.phpdeveloper.org/news/8798</link>
      <description><![CDATA[<p>
The Gentoo linux group has <a href="http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml">made a new package release</a> for the PHP on their distribution:
</p>
<blockquote>
PHP contains several vulnerabilities including buffer and integer overflows which could lead to the remote execution of arbitrary code. [...] There is no known workaround at this time. All PHP users should upgrade to the latest version.
</blockquote>
<p>
You can get more information on the issues that the new package corrects from <a href="http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml">the Gentoo advisory</a> and use their emerge package manager to make the upgrade automatically.
</p>]]></description>
      <pubDate>Mon, 08 Oct 2007 08:45:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: Fedora update for PHP]]></title>
      <guid>http://www.phpdeveloper.org/news/8682</guid>
      <link>http://www.phpdeveloper.org/news/8682</link>
      <description><![CDATA[<p>
As mentioned in <a href="http://secunia.com/advisories/26802/">this advisory</a> on the Secunia website (reposted from the <a href="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00321.html">original advisory</a>) the Fedora Linux group has posted an update for their PHP package to bring it up to date with the recent PHP 5.2.4 release.
</p>
<blockquote>
Fedora has issued an update for php. This fixes a weakness and some vulnerabilities, where some have unknown impacts and others can be exploited by malicious users and malicious, local users to bypass certain security restrictions.
</blockquote>
<p>
You can find the complete list of packages that were updated in <a href="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00321.html">their advisory posting</a> and a brief mention of the easiest way for you to update your distribution (yum).
</p>]]></description>
      <pubDate>Wed, 19 Sep 2007 07:58:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[SecurityReason: Three Advisories for PHP 5.2.4 (dl, iconv_substr & setlocale)]]></title>
      <guid>http://www.phpdeveloper.org/news/8646</guid>
      <link>http://www.phpdeveloper.org/news/8646</link>
      <description><![CDATA[<p>
The SecurityReason website has three new advisories posted concerning the latest release in the PHP 5 series:
</p>
<ul>
<li><a href="http://securityreason.com/securityalert/3119">PHP 5.2.4 <= dl() open_basedir_bypass&code exec&dos</a> - input for the dl() function is not handled correctly and can lead to arbitrary code being loaded and executed
<li><a href="http://securityreason.com/securityalert/3115">PHP <=5.2.4 iconv_substr() denial of service</a> - memory limit issue can be used in a DoS attack
<li><a href="http://securityreason.com/securityalert/3114">PHP < 5.2.4 setlocale() denial of service</a> - memory limit issue can be used for a DoS attack
</ul>
<p>
The dl() overflow is marked as a medium threat (largely because it allows for arbitrary code execution) but the other two are shown as low threat. <a href="http://securityreason.com/securityalert/3119">A patch</a> is also given for the dl() issue to help correct the problem.
</p>]]></description>
      <pubDate>Thu, 13 Sep 2007 09:33:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Zend: Zend Technologies and COMMON Create PHP Advisory Group]]></title>
      <guid>http://www.phpdeveloper.org/news/8277</guid>
      <link>http://www.phpdeveloper.org/news/8277</link>
      <description><![CDATA[<p>
In a <a href="http://www.itjungle.com/tfh/tfh070907-story05.html">new press release</a> (as posted on the ITJungle.com website), Zend has announced a collaboration between it and the <a href="http://www.common.org/">COMMON Group</a> to create a PHP advisory group:
</p>
<blockquote>
<p>
Just before the July 4th holiday, Jim Dillard, the IBM alliance manager at Zend, and Ron Newman, who is chairman of COMMON's Advocacy Team and president of technology consulting firm Newmark Technologies, sent out a joint appeal via email for people to join the Zend Advisory Group. 
</p>
<p>
The idea behind the group is to get together a bunch of COMMON members and have them provide direct input to Zend so the unique capabilities of the System i platform can be addressed more fully by Zend's products and to help Zend better understand how to interface with and deliver products to midrange customers.
</p>
</blockquote>
<p>
Wondering if you (or your company) are in the group they're looking for? Here's some of the requirements:
</p>
<ul>
<li>Are you currently a programmer using the System i?
<li>Have you installed Zend Core for i5/OS?
<li>Do you have a PHP application running now?
<li>Do understand the process of creating a call to the DB2 database?
<li>Can you invoke RPG commands via the PHP toolkit?
</ul>
<p>
If this is you and you'd like ot get in on the group, send an email along to <a href="mailto:Ron_Newman@common.org">Ron Newman</a> for more information.
</p>]]></description>
      <pubDate>Wed, 18 Jul 2007 12:56:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: SUSE update for PHP]]></title>
      <guid>http://www.phpdeveloper.org/news/7909</guid>
      <link>http://www.phpdeveloper.org/news/7909</link>
      <description><![CDATA[<p>
Secunia has release <a href="http://secunia.com/advisories/25056/">a new advisory</a> for SUSE linux users to point them to the update of the PHP packages on their system to correct a highly critical issue.
</p>
<blockquote>
SUSE has issued an update for php. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious people to disclose potentially sensitive information, to bypass certain security restrictions, to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.
</blockquote>
<p>
Operating systems included in the advisory are systems running SUSE Linux, UnitesLinux, and openSUSE linux. Package updates are linked <a href="http://secunia.com/advisories/25056/">from the advisory</a> so you can quickly and easily update your packages.
</p>]]></description>
      <pubDate>Wed, 23 May 2007 16:29:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: phpChess Community Edition Multiple File Inclusion]]></title>
      <guid>http://www.phpdeveloper.org/news/7788</guid>
      <link>http://www.phpdeveloper.org/news/7788</link>
      <description><![CDATA[<p>
Users of the phpChess application for their website should take note of <a href="http://secunia.com/advisories/25147/">this new advisory</a> posted on the Secunia website. It's related to a vulnerability that allows for multiple file inclusion, allowing for malicious code to be included. This issue is for Community Edition versions 2.x.
</p>
<blockquote>
GolD_M has discovered some vulnerabilities in phpChess Community Edition, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
</blockquote>
<p>
The issue surrounds the "root_path" parameter not being properly verified before the include happens. If register_globals is on, this could be overridden and malicious code could be injected. The recommended fix for the issue is to go in and correct the source code, making it validate the location of the file (and that it exists) before it is included.
</p>]]></description>
      <pubDate>Mon, 07 May 2007 11:24:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: Debian Updates for PHP4 and PHP5 Users]]></title>
      <guid>http://www.phpdeveloper.org/news/7734</guid>
      <link>http://www.phpdeveloper.org/news/7734</link>
      <description><![CDATA[<p>
As noted on the security update website, <a href="http://www.secunia.com">Secunia.com</a>, Debian users can now update this distributions with the latest patches for both versions, PHP4 and PHP5.
</p>
<blockquote>
Debian has issued an update for php4/php5. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, malicious users to disclose potentially sensitive information or compromise a vulnerable system, and by malicious people to compromise a vulnerable system.
</blockquote>
<p>
Links to the advisory posts (that include the links to download the updated packages):
<ul>
<li><a href="http://secunia.com/advisories/25025/">For PHP4 Users</a>
<li><a href="http://secunia.com/advisories/25062/">For PHP5 Users</a>
</ul>
It is recommended that Debian users update their installations immediately so as to avoid any kind of security issue that might result from the vulnerability.
</p>]]></description>
      <pubDate>Mon, 30 Apr 2007 12:14:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia: Cisco Products PHP "htmlentities()" and "htmlspecialchars()" Buffer Overflows]]></title>
      <guid>http://www.phpdeveloper.org/news/7711</guid>
      <link>http://www.phpdeveloper.org/news/7711</link>
      <description><![CDATA[<p>
Cicso product users should check out <a href="http://secunia.com/advisories/25047/">this latest issue</a> Secunia has released today - a problem with the htmlentities and htmlspecialchars functions that can lead to buffer overflows.
</p>
<blockquote>
<p>
The vulnerabilities are caused due to boundary errors within the "htmlentities()" and "htmlspecialchars()" functions. If a PHP application uses these functions to process user-supplied input, this can be exploited to cause a heap-based buffer overflow by passing specially crafted data to the affected application.
</p>
<p>
Successful exploitation may allow execution of arbitrary code, but requires that the UTF-8 character set is selected.
</p>
</blockquote>
<p>
Products affected include the Network Analysis Modules (NAM) for Cisco 6500 switch, Cisco 7600 router/Branch Routers and the CiscoWorks Wireless LAN Solution Engine (WLSE) and CiscoWorks Wireless LAN Solution (among others, check out <a href="http://secunia.com/advisories/25047/">the advisory</a> for a more complete list). 
</p>
<p>
There are some patches that have been released to correct this issue (like the one for the Cisco Unified Application Environment) but others are still yet to come. They recommend limiting access to only trusted IPs and devices only to reduce the risk of the problem being exploited.
</p>]]></description>
      <pubDate>Thu, 26 Apr 2007 07:55:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Hardened-PHP Project: WordPress Vulnerability Advisories (XSS & Trackbacks)]]></title>
      <guid>http://www.phpdeveloper.org/news/7039</guid>
      <link>http://www.phpdeveloper.org/news/7039</link>
      <description><![CDATA[<p>
The Hardened-PHP Project has posted two new advisories today, both dealing with WordPress issues - one is a trackback problem with decoding the charset and the other an XSS vulnerability.
</p>
<p>
The <a href="http://www.hardened-php.net/advisory_022007.141.html">first advisory</a> notes that:
</p>
<blockquote>
While testing WordPress it was discovered that WordPress supports trackbacks in different charsets when PHP's mbstring extension is installed. This feature can be abused to bypass WordPress's SQL parameter escaping which leads to an SQL injection vulnerability that can result in a compromise of the admin account and end in a server compromise.
</blockquote>
<p>
The <a href="http://www.hardened-php.net/advisory_012007.140.html">second advisory</a> talks about a problem with the WordPress admin interface that leaves it open to cross-site scripting issues.
</p>
<p>
The WordPress group has already released <a href="http://wordpress.org/download/">an updated version</a> to resolve both of these issues. It is highly recommended that you update your installation immediately to prevent the exploits of either of these vulnerabilities.
</p>]]></description>
      <pubDate>Fri, 05 Jan 2007 13:26:15 -0600</pubDate>
    </item>
  </channel>
</rss>
