com web/php: - add news entry about bad 5.4.2/5.3.12: archive/archive.xml archive/entries/2012-05-06-1.xml

From: Date: Sun, 06 May 2012 22:13:20 +0000
Subject: com web/php: - add news entry about bad 5.4.2/5.3.12: archive/archive.xml archive/entries/2012-05-06-1.xml
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-13466@lists.php.net to get a copy of this message
Commit: 5bff70e7c397b3388a63594ad98e0f9b5c95a857 Author: Pierre Joye <pierre.php@gmail.com> Mon, 7 May 2012 00:13:20 +0200 Parents: 9461157f3773f90c50d424d92ce02280075e4280 Branches: master Link: http://git.php.net/?p=web/php.git;a=commitdiff;h=5bff70e7c397b3388a63594ad98e0f9b5c95a857 Log: - add news entry about bad 5.4.2/5.3.12 Changed paths: M archive/archive.xml A archive/entries/2012-05-06-1.xml Diff: diff --git a/archive/archive.xml b/archive/archive.xml index fe92d19..3619231 100644 --- a/archive/archive.xml +++ b/archive/archive.xml @@ -9,6 +9,7 @@ <uri>http://php.net/contact</uri> <email>php-webmaster@lists.php.net</email> </author> + <xi:include href="entries/2012-05-06-1.xml"/> <xi:include href="entries/2012-05-03-1.xml"/> <xi:include href="entries/2012-04-27-1.xml"/> <xi:include href="entries/2012-04-26-1.xml"/> diff --git a/archive/entries/2012-05-06-1.xml b/archive/entries/2012-05-06-1.xml new file mode 100644 index 0000000..a37df66 --- /dev/null +++ b/archive/entries/2012-05-06-1.xml @@ -0,0 +1,31 @@ +<?xml version="1.0" encoding="utf-8"?> +<entry xmlns="http://www.w3.org/2005/Atom"> + <title>PHP 5.3.12 and 5.4.2 releases about CGI flaw ( CVE-2012-1823)</title> + <id>http://www.php.net/archive/2012.php#id2012-05-06-1</id> + <published>2012-05-06T23:00:36+02:00</published> + <updated>2012-05-06T23:00:36+02:00</updated> + <category term="frontpage" label="PHP.net frontpage news"/> + <link href="http://www.php.net/index.php#id2012-05-03-1" rel="alternate" type="text/html"/> + <link href="http://www.php.net/archive/2012.php#id2012-05-03-1" rel="via" type="text/html"/> + <content type="xhtml"> + <div xmlns="http://www.w3.org/1999/xhtml"> + <p>PHP 5.3.12/5.4.2 do not fix all variations of the CGI issues described + in CVE-2012-1823. It has also come to our attention that some sites use + an insecure cgiwrapper script to run PHP. These scripts will use $* + instead of "$@" to pass parameters to php-cgi which causes a number of + issues. + + <p>Another set of releases is planed for Tuesday, May, 8th. These + releases will fix the CGI flaw and another issue in + apache_request_header (5.4 only).</p> + + <p>However, we recommend to anyone affected with the CGI flaw to migrate + to FastCGI and FPM (or another SAPI like mod_php). CGI is a very old + technology and is really not aimed to be used in today's production + server.</p> + + <p>We apologize for the inconvenience created with these releases and the + (lack of) communications around them.</p> + </div> + </content> +</entry>

« previous php.webmaster (#13466) next »