<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Wed, 19 Jun 2013 21:25:36 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[PHPBuilder.com: Two PHP 5 Security Flaws Found]]></title>
      <guid>http://www.phpdeveloper.org/news/18180</guid>
      <link>http://www.phpdeveloper.org/news/18180</link>
      <description><![CDATA[<p>
As reported in <a href="http://www.phpbuilder.com/articles/application-architecture/security/php-5-security-flaws-CVE-2012-2386-and-CVE-2012-2143.html">this new post</a> on PHPBuilder.com, there are two new security issues that could allow an attacker to execute their own code (note: these are fixed by the latest releases, PHP 5.4.4 and PHP 5.3.14).
</p>
<blockquote>
The flaws are related to each other, with the primary issue being an insecure implementation of the DES within the crypt() function. In his eSecurityPlanet article about <a href="http://www.esecurityplanet.com/patches/open-source-php-and-ruby-on-rails-updated-for-security.html">recent PHP security updates</a>, Sean Michael Kerner provides the details of these two security flaws.
</blockquote>
<p>
The issue stems from a flaw in the DES implementation where certain keys are truncated before the DES digestion and a problem in the <a href="http://php.net/phar">phar</a> extension that could allow for arbitrary code execution. You can find more on these security issues <a href="http://www.esecurityplanet.com/patches/open-source-php-and-ruby-on-rails-updated-for-security.html">here</a>.
</p>]]></description>
      <pubDate>Wed, 04 Jul 2012 21:04:33 -0500</pubDate>
    </item>
  </channel>
</rss>
