store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed Jun 19, 2013 6:56 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 4 posts ] 
Author Message
 Post subject: Critical: php security update
Unread postPosted: Mon Feb 06, 2012 4:12 pm 
Offline
Forum Regular
Forum Regular

Joined: Sat Mar 28, 2009 6:58 pm
Posts: 802
Location: Germany
The PHP development team would like to announce the immediate availability of PHP 5.3.10. This release delivers a critical security fix.
Security Fixes in PHP 5.3.10:
* Fixed arbitrary remote code execution vulnerability reported by Stefan Esser, CVE-2012-0830.
All users are strongly encouraged to upgrade to PHP 5.3.10.

SOURCES:
https://rhn.redhat.com/errata/RHSA-2012-0093.html
http://www.php.net/archive/2012.php#id2012-02-02-1


Top
 Profile  
 
 Post subject: Re: Critical: php security update
Unread postPosted: Mon Feb 06, 2012 4:40 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3265
Location: Chantilly, VA
Thank you for the post.

PHP 5.3.10 was released in the atomic channel last week.

With that said, ASL already protects against this vulnerability, as do the Real Time rules, so if you are running ASL or the real time rules you may not need to upgrade. We believe in defense in depth here at Atomicorp, so upgrading is recommended, but not required.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Critical: php security update
Unread postPosted: Mon Feb 06, 2012 5:49 pm 
Offline
Forum Regular
Forum Regular

Joined: Sat Mar 28, 2009 6:58 pm
Posts: 802
Location: Germany
Fantastic like always.
Sorry for posting even though you already released 5.3.10.
Better one time to much than the other way around :)


Top
 Profile  
 
 Post subject: Re: Critical: php security update
Unread postPosted: Tue Feb 07, 2012 10:20 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3265
Location: Chantilly, VA
No need to apologize, please feel free to post any security advisory that you think is relevant. We, and I'm sure others, definitely appreciate it. I think its always better to be safe that sorry.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 4 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group