Bron: [url=http://www.php.net]PHP.net[/url]
Er is wegens een security bug een nieuwe release van PHP.
Iedereen wordt aangeraden deze nieuwe versie of de patch te installeren!
[url=http://www.php.net/downloads.php]Downloads[/url]
[pagebreak]
Info:
[quote]Due to a security issue found in all versions of PHP (including 3.x and 4.x), a new version of PHP has been released. Details about the security issue are available here. All users of PHP are strongly encouraged to either upgrade to PHP 4.1.2, or install the patch (available for PHP 3.0.18, 4.0.6 and 4.1.0/4.1.1).
[/quote]
Details:
[quote]PHP supports multipart/form-data POST requests (as described in RFC1867) known as POST fileuploads. Unfourtunately there are several flaws in the php_mime_split function that could be used by an attacker to execute arbitrary code. During our research we found out that not only PHP4 but also older versions from the PHP3 tree are vulnerable.
[/quote]
[url=http://security.e-matters.de/advisories/012002.html]Lees meer…[/url]