Re: Did everybody see the security warning at php.net?
| From: | Bo Kleve | Date: | Thu, 28 Feb 2002 12:39:54 +0000 |
| Subject: | Re: Did everybody see the security warning at php.net? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-86589@lists.php.net to get a copy of this message | ||
Is this vulnerability exploitable only if I have an upload page or is it
also possible to use it other ways? From reading the pages I have found I
guess it's only the first way, but I want to be sure.
/BoK
>http://www.php.net/
>
>[27-Feb-2002] Due to a security issue found in all versions of PHP
>(including 3.x and 4.x), a new version of PHP has been released. Details
>about the security issue are available here. All users of PHP are strongly
>encouraged to either upgrade to PHP 4.1.2, or install the patch (available
>for PHP 3.0.18, 4.0.6 and 4.1.0/4.1.1).
>
>http://security.e-matters.de/advisories/012002.html
--------------------------------------------------
Bo Kleve Mail: BoK@UNIT.LiU.SE
Linkoping University Phone: +46 13 281761
Sweden Fax: +46 13 284400