Original URL: http://www.theregister.co.uk/2005/11/01/php_security_vuln/
Shout goes out over PHP security bugs
The script's a killer
Posted in Enterprise Security, 1st November 2005 15:38 GMT
Security researchers have identified numerous new vulnerabilities in PHP - the popular, open source web development environment. The critical security flaws create a possible means for hackers to conduct cross-site scripting attacks, bypass certain security restrictions or even (at least potentially) compromise a vulnerable system.
The vulnerabilities are reported to affect PHP versions 4.4.0 and prior. Users are advised to update to version 4.4.1 (release notes here (http://www.php.net/release_4_4_1.php)). Most of this batch of PHP security vulnerabilities (summary (http://secunia.com/advisories/16502)) were discovered by Stefan Esser, of the Hardened-PHP Project, which has published a series of advisories here (http://www.hardened-php.net/advisories.15.html).
The security bugs described by the Hardened-PHP Project are yet to be developed into s'kiddie friendly exploits. But the past appearance of PHP-targeting worms (http://www.theregister.co.uk/2004/12/21/santy_worm), and the damage they caused, really ought to prompt the rapid deployment of security updates. ®
