Description
The PHP development team would like to announce the immediate availability of PHP 5.2.3. This release continues to improve the security and the stability of the 5.X branch as well as addressing two regressions introduced by the previous 5.2 releases. These regressions relate to the timeout handling over non-blocking SSL connections and the lack of HTTP_RAW_POST_DATA in certain conditions. All users are encouraged to upgrade to this release.
Security Enhancements and Fixes in PHP 5.2.3:
- Fixed an integer overflow inside chunk_split() (by Gerhard Wagner, CVE-2007-2872)
- Fixed possible infinite loop in imagecreatefrompng. (by Xavier Roche, CVE-2007-2756)
- Fixed ext/filter Email Validation Vulnerability (MOPB-45 by Stefan Esser, CVE-2007-1900)
- Fixed bug #41492 (open_basedir/safe_mode bypass inside realpath()) (by bugs dot php dot net at chsc dot dk)
- Improved fix for CVE-2007-1887 to work with non-bundled sqlite2 lib.
- Added mysql_set_charset() to allow runtime altering of connection encoding.
Affected PHP versions (up to 5.2.2).
Remediation
Upgrade PHP to the latest version.
References
Related Vulnerabilities
WordPress Plugin AVH Extended Categories Widgets Unspecified Vulnerability (4.0.2)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Cross-Site Scripting (1.5.22)
WordPress Plugin Image Gallery with Slideshow Multiple Vulnerabilities (1.5.2)
WordPress Plugin WP Statistics Multiple Cross-Site Scripting Vulnerabilities (12.0.1)