Description
-
This alert was generated using only banner information. It may be a false positive.
The PHP development team would like to announce the immediate availability of PHP 5.2.6. This release focuses on improving the stability of the PHP 5.2.x branch with over 120 bug fixes, several of which are security related. All users of PHP are encouraged to upgrade to this release.
Security Enhancements and Fixes in PHP 5.2.6:- Fixed possible stack buffer overflow in the FastCGI SAPI identified by Andrei Nigmatulin.
- Fixed integer overflow in printf() identified by Maksymilian Aciemowicz.
- Fixed security issue detailed in CVE-2008-0599 identified by Ryan Permeh.
- Fixed a safe_mode bypass in cURL identified by Maksymilian Arciemowicz.
- Properly address incomplete multibyte chars inside escapeshellcmd() identified by Stefan Esser.
- Upgraded bundled PCRE to version 7.6
Affected PHP versions (up to 5.2.5).
Remediation
- Upgrade PHP to the latest version.
References
Severity
Classification
Tags
Related Vulnerabilities
- WordPress Plugin KBoard Multiple Vulnerabilities (3.3)
- Drupal Core 4.6.x Arbitrary Code Execution (4.6.0 - 4.6.6)
- WordPress Plugin XCloner-Backup and Restore 'config' Parameter Local File Inclusion (3.0.3)
- WordPress Plugin Photocart Link Local File Inclusion (1.6)
- WordPress Plugin All Video Gallery 'vid' Parameter Multiple SQL Injection Vulnerabilities (1.1)