Major PHP Security Flaws Patched

CYBERSPACE — Several major security flaws in the PHP scripting language were successfully patched this week, plugging up holes that could have allowed attackers to gain control of a server that used the server-side language.

“All users of PHP are strongly encouraged to upgrade to one of these releases as soon as possible,” the PHP Group, a community of software developers who put out official releases of the scripting language, said on its website.

PHP: Hypertext Preprocessing, which allows web pages to generate dynamic content and interact with databases, is often used by bloggers and content management applications.

The new patched versions of PHP, 4.3.10 and 5.0.3, available on the PHP Group’s website address a list of six bugs, including several serious security flaws, which was announced last week by the Hardened-PHP team.

Among the problems mentioned in the group’s list were two errors with the language’s variable unserializer that allowed attackers to execute arbitrary code and to craft strings that could pass execution to shellcode contained within the string itself.

“It is strongly recommended to upgrade to the new PHP releases as soon as possible,” said Hardened-PHP. “A lot of PHP applications expose the easy to exploit unserialize() vulnerability to remote attackers.”

Some of the vulnerable applications built using the scripting languages and identified as vulnerable by the Hardened-PHP group include phpBB2, Invision Board, vBulletin, Woltlab Burning Board 2.x, Serendipity Weblog, phpAds and others.

Bulletin board software phpBB is also currently under attack by the Santy.a worm because of bugs contained within its code that effectively allows SQL injection exploits.

In addition to releasing the vulnerabilities to the PHP-using community, Hardened-PHP also offers its own security-harden version of the language.

Patches for the PHP vulnerabilities are available here.

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Nebraska Legislature Passes Republican's Age Verification Bill With No Votes Against It

Nebraska’s unicameral legislature has passed the state’s version of the age verification bills being sponsored around the country by anti-porn religious conservative activists.

Performers in Meta Blacklisting Lawsuit Seek to Preserve Antitrust Claims

Adult Performance Artists Guild board officers Alana Evans, Kelly Pierce and Ruby have informed a California court that, although they want to drop their lawsuit claiming that Meta conspired with OnlyFans to blacklist rival premium fan platforms’ talent, they may still have antitrust claims that they may pursue in the future.

FSC, Co-Plaintiffs to Ask US Supreme Court to Review Constitutionality of Texas Age Verification Law

Free Speech Coalition (FSC) and its co-plaintiffs in the challenge to Texas’ controversial age verification law have filed a petition before the United States Court of Appeals for the 5th Circuit asking to stay its recent upholding the law because they intend to appeal to the U.S. Supreme Court to review the law’s constitutionality.

FSC Vows to Fight Florida Age Verification Law

Free Speech Coalition (FSC) issued a statement vowing to continue fighting Florida’s age verification law, which was signed by Gov. Ron DeSantis on Monday as part of a comprehensive bill targeting minors’ use of social media.

Kansas Republican Aims to Create New Bureaucracy to 'Investigate' Porn Websites

Republican state legislators succeeded Monday in moving forward Kansas’ version of the age verification bills being sponsored around the country by anti-porn religious conservative activists, despite serious concerns raised by House Democrats about the cost of establishing a new bureaucracy tasked with investigating websites for pornographic content.

SK Intertainment Launches 'Skinfluential Management' Agency, FansFuel Joint Venture

Mr. Skin/Mr. Man parent company SK Intertainment has launched new creator agency Skinfluential Management, as well as a new joint venture with Showbizz Media's creator stats and affiliate marketing platform, FansFuel.

Industry Attorney, Free Speech Champion Clyde DeWitt Passes Away at 75

Noted industry attorney Clyde DeWitt passed away on Friday in Las Vegas at 75, according to friends and colleagues.

APClips Names Avery Jane 'Creator of the Month'

APClips has named Avery Jane its Creator of the Month for March.

JustFor.fans Offers Gumroad Users Platform to Sell NSFW Artwork

JustFor.fans (JFF) is offering Gumroad users a platform to sell NSFW artwork after the latter banned adult content.

Live Cam Academy Offers Free Access to Educational Resources

Live Cam Academy is offering its educational resources for free to content creators and cam models.

Show More