Channel Register®

Original URL: http://www.channelregister.co.uk/2005/11/01/php_security_vuln/

Shout goes out over PHP security bugs

The script's a killer

By John Leyden

Posted in Software & Security, 1st November 2005 15:38 GMT

Free whitepaper – Solid State Drives and High-Speed Memory

Security researchers have identified numerous new vulnerabilities in PHP - the popular, open source web development environment. The critical security flaws create a possible means for hackers to conduct cross-site scripting attacks, bypass certain security restrictions or even (at least potentially) compromise a vulnerable system.

The vulnerabilities are reported to affect PHP versions 4.4.0 and prior. Users are advised to update to version 4.4.1 (release notes here [1]). Most of this batch of PHP security vulnerabilities (summary [2]) were discovered by Stefan Esser, of the Hardened-PHP Project, which has published a series of advisories here [3].

The security bugs described by the Hardened-PHP Project are yet to be developed into s'kiddie friendly exploits. But the past appearance of PHP-targeting worms [4], and the damage they caused, really ought to prompt the rapid deployment of security updates. ®