com web/php: Improve announcement: archive/entries/2012-05-06-1.xml

From: Date: Sun, 06 May 2012 23:16:59 +0000
Subject: com web/php: Improve announcement: archive/entries/2012-05-06-1.xml
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-13468@lists.php.net to get a copy of this message
Commit: dbc06ca6c50066c15bf65b0640262308bc51e661 Author: Rasmus Lerdorf <rasmus@php.net> Sun, 6 May 2012 16:16:59 -0700 Parents: 397f9529404e45dc937f6ed9a5fc3eaeee5ef6b2 Branches: master Link: http://git.php.net/?p=web/php.git;a=commitdiff;h=dbc06ca6c50066c15bf65b0640262308bc51e661 Log: Improve announcement Changed paths: M archive/entries/2012-05-06-1.xml Diff: diff --git a/archive/entries/2012-05-06-1.xml b/archive/entries/2012-05-06-1.xml index a37df66..ac91ac7 100644 --- a/archive/entries/2012-05-06-1.xml +++ b/archive/entries/2012-05-06-1.xml @@ -1,31 +1,39 @@ -<?xml version="1.0" encoding="utf-8"?> -<entry xmlns="http://www.w3.org/2005/Atom"> - <title>PHP 5.3.12 and 5.4.2 releases about CGI flaw ( CVE-2012-1823)</title> - <id>http://www.php.net/archive/2012.php#id2012-05-06-1</id> - <published>2012-05-06T23:00:36+02:00</published> - <updated>2012-05-06T23:00:36+02:00</updated> - <category term="frontpage" label="PHP.net frontpage news"/> - <link href="http://www.php.net/index.php#id2012-05-03-1" rel="alternate" type="text/html"/> - <link href="http://www.php.net/archive/2012.php#id2012-05-03-1" rel="via" type="text/html"/> - <content type="xhtml"> - <div xmlns="http://www.w3.org/1999/xhtml"> - <p>PHP 5.3.12/5.4.2 do not fix all variations of the CGI issues described - in CVE-2012-1823. It has also come to our attention that some sites use - an insecure cgiwrapper script to run PHP. These scripts will use $* - instead of "$@" to pass parameters to php-cgi which causes a number of - issues. - - <p>Another set of releases is planed for Tuesday, May, 8th. These - releases will fix the CGI flaw and another issue in - apache_request_header (5.4 only).</p> - - <p>However, we recommend to anyone affected with the CGI flaw to migrate - to FastCGI and FPM (or another SAPI like mod_php). CGI is a very old - technology and is really not aimed to be used in today's production - server.</p> - - <p>We apologize for the inconvenience created with these releases and the - (lack of) communications around them.</p> - </div> - </content> -</entry> +<?xml version="1.0" encoding="utf-8"?> +<entry xmlns="http://www.w3.org/2005/Atom"> + <title>PHP 5.3.12 and 5.4.2 releases about CGI flaw ( CVE-2012-1823)</title> + <id>http://www.php.net/archive/2012.php#id2012-05-06-1</id> + <published>2012-05-06T23:00:36+02:00</published> + <updated>2012-05-06T23:00:36+02:00</updated> + <category term="frontpage" label="PHP.net frontpage news"/> + <link href="http://www.php.net/index.php#id2012-05-03-1" rel="alternate" type="text/html"/> + <link href="http://www.php.net/archive/2012.php#id2012-05-03-1" rel="via" type="text/html"/> + <content type="xhtml"> + <div xmlns="http://www.w3.org/1999/xhtml"> + <p>PHP 5.3.12/5.4.2 do not fix all variations of the CGI issues described + in CVE-2012-1823. It has also come to our attention that some sites use + an insecure cgiwrapper script to run PHP. These scripts will use $* + instead of "$@" to pass parameters to php-cgi which causes a number of + issues. Again, people using mod_php or php-fpm are not affected.</p> + + <p> + One way to address these CGI issues is to throw away the query parameters if they + contain a '-' and no '='. It can be done using Apache's mod_rewrite like this: + + <pre> + RewriteCond %{QUERY_STRING} ^.*(%2d|-)[^=]+$ [NC] + RewriteRule ^(.*) $1? [L] + </pre> + + Note that this will block otherwise safe requests like ?top-40 so if you + are using mod_cgi and have query parameters that look like that, adjust your + regex accordingly.</p> + + <p>Another set of releases are planned for Tuesday, May, 8th. These + releases will fix the CGI flaw and another CGI-related issue in + apache_request_header (5.4 only).</p> + + <p>We apologize for the inconvenience created with these releases and the + (lack of) communications around them.</p> + </div> + </content> +</entry>

« previous php.webmaster (#13468) next »