com web/php: - add news entry about bad 5.4.2/5.3.12: archive/archive.xml archive/entries/2012-05-06-1.xml
| From: | Pierre Joye | Date: | Sun, 06 May 2012 22:13:20 +0000 |
| Subject: | com web/php: - add news entry about bad 5.4.2/5.3.12: archive/archive.xml archive/entries/2012-05-06-1.xml | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-13466@lists.php.net to get a copy of this message | ||
Commit: 5bff70e7c397b3388a63594ad98e0f9b5c95a857
Author: Pierre Joye <pierre.php@gmail.com> Mon, 7 May 2012 00:13:20 +0200
Parents: 9461157f3773f90c50d424d92ce02280075e4280
Branches: master
Link: http://git.php.net/?p=web/php.git;a=commitdiff;h=5bff70e7c397b3388a63594ad98e0f9b5c95a857
Log:
- add news entry about bad 5.4.2/5.3.12
Changed paths:
M archive/archive.xml
A archive/entries/2012-05-06-1.xml
Diff:
diff --git a/archive/archive.xml b/archive/archive.xml
index fe92d19..3619231 100644
--- a/archive/archive.xml
+++ b/archive/archive.xml
@@ -9,6 +9,7 @@
<uri>http://php.net/contact</uri>
<email>php-webmaster@lists.php.net</email>
</author>
+ <xi:include href="entries/2012-05-06-1.xml"/>
<xi:include href="entries/2012-05-03-1.xml"/>
<xi:include href="entries/2012-04-27-1.xml"/>
<xi:include href="entries/2012-04-26-1.xml"/>
diff --git a/archive/entries/2012-05-06-1.xml b/archive/entries/2012-05-06-1.xml
new file mode 100644
index 0000000..a37df66
--- /dev/null
+++ b/archive/entries/2012-05-06-1.xml
@@ -0,0 +1,31 @@
+<?xml version="1.0" encoding="utf-8"?>
+<entry xmlns="http://www.w3.org/2005/Atom">
+ <title>PHP 5.3.12 and 5.4.2 releases about CGI flaw ( CVE-2012-1823)</title>
+ <id>http://www.php.net/archive/2012.php#id2012-05-06-1</id>
+ <published>2012-05-06T23:00:36+02:00</published>
+ <updated>2012-05-06T23:00:36+02:00</updated>
+ <category term="frontpage" label="PHP.net frontpage news"/>
+ <link href="http://www.php.net/index.php#id2012-05-03-1"
rel="alternate" type="text/html"/>
+ <link href="http://www.php.net/archive/2012.php#id2012-05-03-1"
rel="via" type="text/html"/>
+ <content type="xhtml">
+ <div xmlns="http://www.w3.org/1999/xhtml">
+ <p>PHP 5.3.12/5.4.2 do not fix all variations of the CGI issues described
+ in CVE-2012-1823. It has also come to our attention that some sites use
+ an insecure cgiwrapper script to run PHP. These scripts will use $*
+ instead of "$@" to pass parameters to php-cgi which causes a number of
+ issues.
+
+ <p>Another set of releases is planed for Tuesday, May, 8th. These
+ releases will fix the CGI flaw and another issue in
+ apache_request_header (5.4 only).</p>
+
+ <p>However, we recommend to anyone affected with the CGI flaw to migrate
+ to FastCGI and FPM (or another SAPI like mod_php). CGI is a very old
+ technology and is really not aimed to be used in today's production
+ server.</p>
+
+ <p>We apologize for the inconvenience created with these releases and the
+ (lack of) communications around them.</p>
+ </div>
+ </content>
+</entry>