<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Wed, 22 May 2013 22:37:36 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[Community News: rPath Linux Updates PHP5 Packages]]></title>
      <guid>http://www.phpdeveloper.org/news/9081</guid>
      <link>http://www.phpdeveloper.org/news/9081</link>
      <description><![CDATA[<p>
The rPath linux group has <a href="http://lists.rpath.com/pipermail/security-announce/2007-November/000277.html">released another update</a> for the PHP5 packages in their distribution:
</p>
<blockquote>
Previous versions of the php5 package contain multiple vulnerabilities, the most serious of which involve several Denial of Service attacks (application crashes and temporary application hangs).  It is not currently known that these vulnerabilities can be exploited to execute malicious code.
</blockquote>
<p>
You can get the <a href="https://issues.rpath.com/browse/RPL-1943">specifics</a> of what's being fixed as well as download the latest packages from the rpath.com website.
</p>]]></description>
      <pubDate>Tue, 20 Nov 2007 12:03:00 -0600</pubDate>
    </item>
    <item>
      <title><![CDATA[Community News: rPath Updates PHP, PHP-MySQL and PHP-PGSQL Packages]]></title>
      <guid>http://www.phpdeveloper.org/news/8904</guid>
      <link>http://www.phpdeveloper.org/news/8904</link>
      <description><![CDATA[<p>
rPath linux has <a href="http://lists.rpath.com/pipermail/security-announce/2007-October/000269.html">issued an update</a> to their packages for PHP, PHP-MySQL and PHP-PGSql to correct issues that could make it possible for a remote user to gain unauthorized access.
</p>
<blockquote>
his fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions or by malicious people to potentially compromise a vulnerable system.
</blockquote>
<p>
References and links to the update information can be found in their <a href="http://lists.rpath.com/pipermail/security-announce/2007-October/000269.html">original advisory</a>.
</p>]]></description>
      <pubDate>Thu, 25 Oct 2007 10:31:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: rPath Update for Multiple php Packages]]></title>
      <guid>http://www.phpdeveloper.org/news/8671</guid>
      <link>http://www.phpdeveloper.org/news/8671</link>
      <description><![CDATA[<p>
According to <a href="http://secunia.com/advisories/26838/">this new advisory</a> on the Secunia website, rPath has updated more of their PHP packages and has marked the update as "moderately critical" to keeping your systems safe.
</p>
<blockquote>
rPath has issued an update for multiple php packages. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious, local users and malicious users to bypass certain security restrictions.
</blockquote>
<p>
The <a href="http://lists.rpath.com/pipermail/security-announce/2007-September/000244.html">original advisory</a> has links to the updated versions and to references as to what has changed.
</p>
<blockquote>
In its default configuration, rPath Linux 1 does not install php5 and is thus not vulnerable to these attacks; however, systems to which php5 has been added may be vulnerable to one or more of these attacks.
</blockquote>]]></description>
      <pubDate>Tue, 18 Sep 2007 07:51:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia: rPath Update for gd and Multiple php Packages]]></title>
      <guid>http://www.phpdeveloper.org/news/8600</guid>
      <link>http://www.phpdeveloper.org/news/8600</link>
      <description><![CDATA[<p>
As mentioned in <a href="http://secunia.com/advisories/26663/">this Secunia advisory</a> today, rPath has release updates to several packages today including a few PHP ones and GD library updates.
</p>
<blockquote>
rPath has issued an update for gd and multiple php packages. This fixes some vulnerabilities, where some have an unknown impact and others can potentially be exploited to cause a DoS (Denial of Service).
</blockquote>
<p>
The update is marked as "moderately critical" so it's recommended that users update their installations as soon as possible. You can find out more information and get the links to download the packages from <a href="http://lists.rpath.com/pipermail/security-announce/2007-September/000233.html">the original advisory post</a>.
</p>]]></description>
      <pubDate>Thu, 06 Sep 2007 09:43:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: rPath update for gd, php, php-mysql, and php-pgsql]]></title>
      <guid>http://www.phpdeveloper.org/news/8006</guid>
      <link>http://www.phpdeveloper.org/news/8006</link>
      <description><![CDATA[<p>
Secunia has posted <a href="http://secunia.com/advisories/25590/">this advisory</a> for rPath users to point out an update to several packages including gd, php, php-mysql, and php-pgsql.
</p>
<blockquote>
rPath has issued an update for gd, php, php-mysql, and php-pgsql. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
</blockquote>
<p>
Users can grab the updated packages as linked to from <a href="http://lists.rpath.com/pipermail/security-announce/2007-June/000196.html">the original advisory notice</a> on the rPath mailing list:
</p>
<blockquote>
Previous versions of the gd and php packages are vulnerable to a Denial of Service attack in which an attacker can use a truncated PNG image to cause unbounded CPU consumption.  The libgd library is not exposed via any privileged or remote interfaces within rPath Linux per se, but it is exposed by some web applications, such as php (which provides its own internal version of libgd).
</blockquote>]]></description>
      <pubDate>Fri, 08 Jun 2007 08:49:00 -0500</pubDate>
    </item>
  </channel>
</rss>
