Description
The PHP development team would like to announce the immediate availability of PHP 5.2.6. This release focuses on improving the stability of the PHP 5.2.x branch with over 120 bug fixes, several of which are security related. All users of PHP are encouraged to upgrade to this release.
Security Enhancements and Fixes in PHP 5.2.6:
- Fixed possible stack buffer overflow in the FastCGI SAPI identified by Andrei Nigmatulin.
- Fixed integer overflow in printf() identified by Maksymilian Aciemowicz.
- Fixed security issue detailed in CVE-2008-0599 identified by Ryan Permeh.
- Fixed a safe_mode bypass in cURL identified by Maksymilian Arciemowicz.
- Properly address incomplete multibyte chars inside escapeshellcmd() identified by Stefan Esser.
- Upgraded bundled PCRE to version 7.6
Affected PHP versions (up to 5.2.5).
Remediation
Upgrade PHP to the latest version.
References
Related Vulnerabilities
WordPress Plugin Tutor LMS-eLearning and online course solution Security Bypass (2.7.0)
Joomla Improper Input Validation Vulnerability (CVE-2020-35616)
WordPress Plugin Crony Cronjob Manager Multiple Vulnerabilities (0.4.4)
WordPress Plugin WP Support Plus Responsive Ticket System Multiple Vulnerabilities (4.1)
WordPress Plugin Google Shortlink by BestWebSoft Cross-Site Scripting (1.5.2)