<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Fri, 04 Jul 2008 16:57:52 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[PHP.net: PHP 5.2.6 Released]]></title>
      <guid>http://www.phpdeveloper.org/news/10094</guid>
      <link>http://www.phpdeveloper.org/news/10094</link>
      <description><![CDATA[<p>
The PHP development team has released the latest version in the PHP 5.2.x series today - <a href="http://www.php.net/index.php#id2008-05-01-1">version 5.2.6</a>:
</p>
<blockquote>
This release focuses on improving the stability ofthe PHP 5.2.x branch with over 120 bug fixes, several of which are security related.All users of PHP are encouraged to upgrade to this release. Further details about the PHP 5.2.6 release can be found in the release announcement for 5.2.6, the full list of changes is available in the ChangeLog for PHP 5.
</blockquote>
<p>
Security updates include prevention of a buffer overflow in FastCGI mode, an integer overflow in printf, correction for a safe_mode bypass method in cURL and the bundling of PCRE 7.6 to update the regular expression functionality of the language.
</p>
<p>
You can grab this latest release from <a href="http://www.php.net/downloads.php">the downloads page</a> on PHP.net (or your favorite mirror) - both the source and the Windows binaries.
</p>]]></description>
      <pubDate>Fri, 02 May 2008 07:51:13 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia: Cisco Products PHP "htmlentities()" and "htmlspecialchars()" Buffer Overflows]]></title>
      <guid>http://www.phpdeveloper.org/news/7711</guid>
      <link>http://www.phpdeveloper.org/news/7711</link>
      <description><![CDATA[<p>
Cicso product users should check out <a href="http://secunia.com/advisories/25047/">this latest issue</a> Secunia has released today - a problem with the htmlentities and htmlspecialchars functions that can lead to buffer overflows.
</p>
<blockquote>
<p>
The vulnerabilities are caused due to boundary errors within the "htmlentities()" and "htmlspecialchars()" functions. If a PHP application uses these functions to process user-supplied input, this can be exploited to cause a heap-based buffer overflow by passing specially crafted data to the affected application.
</p>
<p>
Successful exploitation may allow execution of arbitrary code, but requires that the UTF-8 character set is selected.
</p>
</blockquote>
<p>
Products affected include the Network Analysis Modules (NAM) for Cisco 6500 switch, Cisco 7600 router/Branch Routers and the CiscoWorks Wireless LAN Solution Engine (WLSE) and CiscoWorks Wireless LAN Solution (among others, check out <a href="http://secunia.com/advisories/25047/">the advisory</a> for a more complete list). 
</p>
<p>
There are some patches that have been released to correct this issue (like the one for the Cisco Unified Application Environment) but others are still yet to come. They recommend limiting access to only trusted IPs and devices only to reduce the risk of the problem being exploited.
</p>]]></description>
      <pubDate>Thu, 26 Apr 2007 07:55:00 -0500</pubDate>
    </item>
  </channel>
</rss>
