com web/php: Improve announcement: archive/entries/2012-05-06-1.xml
| From: | Rasmus Lerdorf | Date: | Sun, 06 May 2012 23:16:59 +0000 |
| Subject: | com web/php: Improve announcement: archive/entries/2012-05-06-1.xml | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-13468@lists.php.net to get a copy of this message | ||
Commit: dbc06ca6c50066c15bf65b0640262308bc51e661
Author: Rasmus Lerdorf <rasmus@php.net> Sun, 6 May 2012 16:16:59 -0700
Parents: 397f9529404e45dc937f6ed9a5fc3eaeee5ef6b2
Branches: master
Link: http://git.php.net/?p=web/php.git;a=commitdiff;h=dbc06ca6c50066c15bf65b0640262308bc51e661
Log:
Improve announcement
Changed paths:
M archive/entries/2012-05-06-1.xml
Diff:
diff --git a/archive/entries/2012-05-06-1.xml b/archive/entries/2012-05-06-1.xml
index a37df66..ac91ac7 100644
--- a/archive/entries/2012-05-06-1.xml
+++ b/archive/entries/2012-05-06-1.xml
@@ -1,31 +1,39 @@
-<?xml version="1.0" encoding="utf-8"?>
-<entry xmlns="http://www.w3.org/2005/Atom">
- <title>PHP 5.3.12 and 5.4.2 releases about CGI flaw ( CVE-2012-1823)</title>
- <id>http://www.php.net/archive/2012.php#id2012-05-06-1</id>
- <published>2012-05-06T23:00:36+02:00</published>
- <updated>2012-05-06T23:00:36+02:00</updated>
- <category term="frontpage" label="PHP.net frontpage news"/>
- <link href="http://www.php.net/index.php#id2012-05-03-1"
rel="alternate" type="text/html"/>
- <link href="http://www.php.net/archive/2012.php#id2012-05-03-1"
rel="via" type="text/html"/>
- <content type="xhtml">
- <div xmlns="http://www.w3.org/1999/xhtml">
- <p>PHP 5.3.12/5.4.2 do not fix all variations of the CGI issues described
- in CVE-2012-1823. It has also come to our attention that some sites use
- an insecure cgiwrapper script to run PHP. These scripts will use $*
- instead of "$@" to pass parameters to php-cgi which causes a number of
- issues.
-
- <p>Another set of releases is planed for Tuesday, May, 8th. These
- releases will fix the CGI flaw and another issue in
- apache_request_header (5.4 only).</p>
-
- <p>However, we recommend to anyone affected with the CGI flaw to migrate
- to FastCGI and FPM (or another SAPI like mod_php). CGI is a very old
- technology and is really not aimed to be used in today's production
- server.</p>
-
- <p>We apologize for the inconvenience created with these releases and the
- (lack of) communications around them.</p>
- </div>
- </content>
-</entry>
+<?xml version="1.0" encoding="utf-8"?>
+<entry xmlns="http://www.w3.org/2005/Atom">
+ <title>PHP 5.3.12 and 5.4.2 releases about CGI flaw ( CVE-2012-1823)</title>
+ <id>http://www.php.net/archive/2012.php#id2012-05-06-1</id>
+ <published>2012-05-06T23:00:36+02:00</published>
+ <updated>2012-05-06T23:00:36+02:00</updated>
+ <category term="frontpage" label="PHP.net frontpage news"/>
+ <link href="http://www.php.net/index.php#id2012-05-03-1"
rel="alternate" type="text/html"/>
+ <link href="http://www.php.net/archive/2012.php#id2012-05-03-1"
rel="via" type="text/html"/>
+ <content type="xhtml">
+ <div xmlns="http://www.w3.org/1999/xhtml">
+ <p>PHP 5.3.12/5.4.2 do not fix all variations of the CGI issues described
+ in CVE-2012-1823. It has also come to our attention that some sites use
+ an insecure cgiwrapper script to run PHP. These scripts will use $*
+ instead of "$@" to pass parameters to php-cgi which causes a number of
+ issues. Again, people using mod_php or php-fpm are not affected.</p>
+
+ <p>
+ One way to address these CGI issues is to throw away the query parameters if they
+ contain a '-' and no '='. It can be done using Apache's mod_rewrite
like this:
+
+ <pre>
+ RewriteCond %{QUERY_STRING} ^.*(%2d|-)[^=]+$ [NC]
+ RewriteRule ^(.*) $1? [L]
+ </pre>
+
+ Note that this will block otherwise safe requests like ?top-40 so if you
+ are using mod_cgi and have query parameters that look like that, adjust your
+ regex accordingly.</p>
+
+ <p>Another set of releases are planned for Tuesday, May, 8th. These
+ releases will fix the CGI flaw and another CGI-related issue in
+ apache_request_header (5.4 only).</p>
+
+ <p>We apologize for the inconvenience created with these releases and the
+ (lack of) communications around them.</p>
+ </div>
+ </content>
+</entry>