News Feed
Jobs Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

PHPClasses.org:
Another Serious Security Bug on PHP 5.3.9
February 06, 2012 @ 14:16:22

On the PHPClasses.org blog there's a new post detailing an issue that came up in the PHP 5.3.9 release that caused a large security issue (PHP 5.3.10 has, however, already been released to correct the issue).

PHP 5.3.9 release was mostly meant to fix a security bug, but it introduced a new more serious bug. PHP 5.3.10 was just released to fix this issue. [...] This time it is a bug that allows arbitrary remote code execution. This means that it allows to run arbitrary code on the server, injected by an eventual attacker, so it can be used to cause many types of damage inside a server.

The upgrade to PHP 5.3.10 is highly recommended to prevent this issue from effecting your applications. The post also mentions the dropping of Suhosin support (a security plugin for PHP) on the Debian linux distribution's default installation and how the PHP community has reacted to the decision.

0 comments voice your opinion now!
security bug release update suhosin


blog comments powered by Disqus

Similar Posts

Travis Swicegood's Blog: Some new PEAR channel code

php|architect: September 2006 Issue Released

PHP.net: PHP 5.5.9 is ready for download

PHPFreaks.com: Hardening PHP with Suhosin

Hardened-PHP Project: PHP HTML Entity Encoder Heap Overflow Vulnerability


Community Events











Don't see your event here?
Let us know!


podcast facebook hack release language introduction security framework dependency package series install overview symfony2 opinion hhvm composer component application unittest

All content copyright, 2014 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework