Developers: PHP Vulnerabilities Announced

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • sfoma
    Junior Member
    • Mar 2004
    • 15

    #1

    Developers: PHP Vulnerabilities Announced

    From Slashdot -

    Posted by michael on Friday December 17, @12:20PM
    from the rated-o-for-overtime dept.
    Simone Klassen writes "The Hardened-PHP Project has announced several serious and according to them, easy-to-exploit vulnerabilities within PHP. A flaw within the function unserialize() is rated as very critical for millions of PHP servers, because it is exposed to remote attackers through lots of very popular webapplications. The list includes forum software like phpBB2, WBB2, Invision Board and vBulletin. It is time to upgrade now."
  • sdjl
    Senior Member
    • Mar 2004
    • 502

    #2
    That gives no detail as to what versions of PHP are affected, if any.
    -----
    Do you fear the obsolescence of the metanarrative apparatus of legitimation?

    Comment

    • sfoma
      Junior Member
      • Mar 2004
      • 15

      #3
      for version information please see the alerts on http://www.php.net/

      Comment

      • sdjl
        Senior Member
        • Mar 2004
        • 502

        #4
        I should imagine cPanel will make an upgrade available very shortly
        -----
        Do you fear the obsolescence of the metanarrative apparatus of legitimation?

        Comment

        • anguz
          Member
          • Mar 2004
          • 47

          #5
          Originally posted by sdjl
          That gives no detail as to what versions of PHP are affected, if any.
          Earlier than 4.3.10 or 5.0.3.
          The list includes forum software like phpBB2, WBB2, Invision Board and vBulletin. It is time to upgrade now.
          In SMF we already put out a fix for the vulnerability.

          Comment

          • oarenj
            Junior Member
            • Jun 2004
            • 5

            #6
            So we cannot fix this issue ourselves, we have to wait for Andrew to do it? Any time frame? Hours, weeks, days, never?

            I have upgraded to the newest phpBB, but one of my sites keeps getting infected - I have to restore the board every hour or so. Which makes for some pretty upset folks..

            If there is a way we can fix this ourselves, like update PHP ourselves - PLEASE let us know!

            Comment

            • -Oz-
              Senior Member
              • Mar 2004
              • 545

              #7
              I just killed the forums because of this.
              Dan Blomberg

              Comment

              • ChrisTech
                Senior Member
                • Mar 2004
                • 530

                #8
                Originally posted by oarenj
                So we cannot fix this issue ourselves, we have to wait for Andrew to do it? Any time frame? Hours, weeks, days, never?

                I have upgraded to the newest phpBB, but one of my sites keeps getting infected - I have to restore the board every hour or so. Which makes for some pretty upset folks..

                If there is a way we can fix this ourselves, like update PHP ourselves - PLEASE let us know!

                Check the Annoucement section
                We will be beginning to upgrade the PHP version on all servers to 4.3.10 very shortly. I will continue to update this thread with the current progress on this. cpanel04 - complete cpanel05 - complete cpanel08 - complete cpanel09b - complete cpanel10 - complete cpanel11 - complete cpanel12 - complete cpanel13 -
                Hosting at Dathorn since March 2003!

                My Interwebs speed on Charter Cable!

                Comment

                • anguz
                  Member
                  • Mar 2004
                  • 47

                  #9
                  Originally posted by ChrisTech
                  Very cool. I noticed he also updated Zend Optimizer, many other hosts didn't and had to be told.

                  Comment

                  • AndrewT
                    Administrator
                    • Mar 2004
                    • 3655

                    #10
                    Yes, ZendOptimizer was ugpraded to 2.5.7 as well. This actually came to our attention when we first upgraded to cpanel04 - if this is not done there are many scripts that will have problems.

                    Comment

                    • anguz
                      Member
                      • Mar 2004
                      • 47

                      #11
                      Originally posted by AndrewT
                      Yes, ZendOptimizer was ugpraded to 2.5.7 as well. This actually came to our attention when we first upgraded to cpanel04 - if this is not done there are many scripts that will have problems.
                      Indeed. Thank you very much for always being on the ball.

                      Comment

                      Working...