<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Thu, 20 Jun 2013 06:43:01 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[Security News: Open SUSE Update for PHP4/PHP5 Packages]]></title>
      <guid>http://www.phpdeveloper.org/news/9520</guid>
      <link>http://www.phpdeveloper.org/news/9520</link>
      <description><![CDATA[<p>
The Open SUSE group has <a href="http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html">released an update</a> for a list of their software to bring their PHP4 and PHP5 packages up to date.
</p>
<blockquote>
php5 was updated to version 5.2.5 to fix several security
vulnerabilities. For php4 on SLES9 the patches were backported.
</blockquote>
<p>
You can find out more about the issues corrected as well as links to the packages that have been updated in <a href="http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html">the advisory message</a>.
</p>]]></description>
      <pubDate>Tue, 29 Jan 2008 13:58:00 -0600</pubDate>
    </item>
    <item>
      <title><![CDATA[Community News: Avaya Products PHP Multiple Vulnerabilities]]></title>
      <guid>http://www.phpdeveloper.org/news/8977</guid>
      <link>http://www.phpdeveloper.org/news/8977</link>
      <description><![CDATA[<p>
As mentioned in <a href="http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm">this new security advisory</a> from Avaya, there's a risk that the PHP version included with their Messaging systems could provide a hole for a would-be attacker to gain access.
</p>
<p>
Issues have been reported in the following:
</p>
<ul>
<li>integer overflow vulnerabilities in the PHP gd extension
<li>integer overflow vulnerability in the PHP chunk_split function
<li>a security update has introduced a bug into PHP session cookie handling
<li>vulnerability in the PHP money_format function
<li>vulnerability in the PHP wordwrap function
<li>vulnerability in PHP session cookie handling
<li>vulnerability in the PHP gc extension
</ul>
<p>
The <a href="http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm">advisory</a> contains links to more information from RedHat on these issues and includes a list of systems effected as well as recommended actions to take. 
</p>]]></description>
      <pubDate>Tue, 06 Nov 2007 07:56:00 -0600</pubDate>
    </item>
    <item>
      <title><![CDATA[Community News: Red Hat Security Package Update]]></title>
      <guid>http://www.phpdeveloper.org/news/8732</guid>
      <link>http://www.phpdeveloper.org/news/8732</link>
      <description><![CDATA[<p>
The Red Hat linux group has <a href="http://secunia.com/advisories/26967/">issued an update</a> for their PHP packages today:
</p>
<blockquote>
Red Hat has issued an update for php. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and by malicious people to bypass certain security restrictions and cause a DoS (Denial of Service).
</blockquote>
<p>
You can get more information about this moderate level advisory from <a href="http://rhn.redhat.com/errata/RHSA-2007-0889.html">the Red Hat advisory</a> including the affected products and the list of packages that should be updated to bring your installation up to date.
</p>]]></description>
      <pubDate>Wed, 26 Sep 2007 12:02:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: Fedora update for PHP]]></title>
      <guid>http://www.phpdeveloper.org/news/8719</guid>
      <link>http://www.phpdeveloper.org/news/8719</link>
      <description><![CDATA[<p>
Via <a href="http://secunia.com/advisories/26930/">this Secunia advisory</a> posted today, there's information about the update the Fedora Linux group has made to the PHP package included in their distribution. According to the release:
</p>
<blockquote>
This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and by malicious people to bypass certain security restrictions and cause a DoS (Denial of Service).
</blockquote>
<p>
The <a href="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00354.html">original advisory post</a> has more details on what the update fixes as well as <a href="http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/">the link</a> to download the RPM packages to update your system. You can either manually download them or use the "yum" system to handle things a bit more automatically.
</p>]]></description>
      <pubDate>Tue, 25 Sep 2007 07:52:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: Red Hat Update for PHP]]></title>
      <guid>http://www.phpdeveloper.org/news/8698</guid>
      <link>http://www.phpdeveloper.org/news/8698</link>
      <description><![CDATA[<p>
On the Secunia site today, there's a <a href="http://secunia.com/advisories/26871/">new advisory</a> posted for users of Red Hat linux - an update to the system's PHP packages.
</p>
<blockquote>
Red Hat has issued an update for php. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and by malicious people to bypass certain security restrictions and cause a DoS (Denial of Service).
</blockquote>
<p>
The <a href="http://rhn.redhat.com/errata/RHSA-2007-0890.html">original advisory</a> has more details on what the patch fixes and the checksum information for the update packages for all OSes.
</p>]]></description>
      <pubDate>Fri, 21 Sep 2007 07:54:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: Fedora update for PHP]]></title>
      <guid>http://www.phpdeveloper.org/news/8682</guid>
      <link>http://www.phpdeveloper.org/news/8682</link>
      <description><![CDATA[<p>
As mentioned in <a href="http://secunia.com/advisories/26802/">this advisory</a> on the Secunia website (reposted from the <a href="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00321.html">original advisory</a>) the Fedora Linux group has posted an update for their PHP package to bring it up to date with the recent PHP 5.2.4 release.
</p>
<blockquote>
Fedora has issued an update for php. This fixes a weakness and some vulnerabilities, where some have unknown impacts and others can be exploited by malicious users and malicious, local users to bypass certain security restrictions.
</blockquote>
<p>
You can find the complete list of packages that were updated in <a href="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00321.html">their advisory posting</a> and a brief mention of the easiest way for you to update your distribution (yum).
</p>]]></description>
      <pubDate>Wed, 19 Sep 2007 07:58:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: rPath Update for Multiple php Packages]]></title>
      <guid>http://www.phpdeveloper.org/news/8671</guid>
      <link>http://www.phpdeveloper.org/news/8671</link>
      <description><![CDATA[<p>
According to <a href="http://secunia.com/advisories/26838/">this new advisory</a> on the Secunia website, rPath has updated more of their PHP packages and has marked the update as "moderately critical" to keeping your systems safe.
</p>
<blockquote>
rPath has issued an update for multiple php packages. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious, local users and malicious users to bypass certain security restrictions.
</blockquote>
<p>
The <a href="http://lists.rpath.com/pipermail/security-announce/2007-September/000244.html">original advisory</a> has links to the updated versions and to references as to what has changed.
</p>
<blockquote>
In its default configuration, rPath Linux 1 does not install php5 and is thus not vulnerable to these attacks; however, systems to which php5 has been added may be vulnerable to one or more of these attacks.
</blockquote>]]></description>
      <pubDate>Tue, 18 Sep 2007 07:51:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: Joomla! Multiple Vulnerabilities]]></title>
      <guid>http://www.phpdeveloper.org/news/8349</guid>
      <link>http://www.phpdeveloper.org/news/8349</link>
      <description><![CDATA[<p>
Secunia.com <a href="http://secunia.com/advisories/26239/">reports that</a> multiple vulnerabilities have been found in the Joomla! content management system:
</p>
<blockquote>
Some vulnerabilities have been reported in Joomla!, which can be exploited by malicious people to conduct session fixation attacks, cross-site scripting attacks or HTTP response splitting attacks.
</blockquote>
<p>
The issues are marked as "less critical" but users should still <a href="http://joomlacode.org/gf/project/joomla/frs/">update to the latest version</a> to avoid these issues: 
</p>
<ul>
<li>Certain unspecified input passed in com_search, com_content and mod_login is not properly sanitised before being returned to a user
<li>Input passed to the "url" parameter is not properly sanitised before being returned to the user. This can be exploited to insert arbitrary HTTP headers.
<li>An error exists in the handling of sessions and can be exploited to hijack another user's session by tricking the user into logging in after following a specially crafted link.
</ul>
<p>
See the <a href="http://www.joomla.org/content/view/3677/1/">original advisory post here</a>.
</p>]]></description>
      <pubDate>Mon, 30 Jul 2007 10:26:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: Ubuntu update for PHP]]></title>
      <guid>http://www.phpdeveloper.org/news/8273</guid>
      <link>http://www.phpdeveloper.org/news/8273</link>
      <description><![CDATA[<p>
Secunia.com has <a href="http://secunia.com/advisories/26102/">posted about</a> the latest PHP package update for the Ubuntu linux distribution in a "highly critical" level update for relases 6.06, 6.10 and 7.04.
</p>
<blockquote>
Ubuntu has issued an update for php. This fixes a vulnerability and a weakness, which can be exploited by malicious people to bypass certain security restrictions or potentially compromise a vulnerable system.
</blockquote>
<p>
<a href="http://secunia.com/advisories/26102/">The post</a> has links to all of the packages for every type of the distribution, including the architecture independent packages. Click on over and grab your update to bring your system up to date and safe.
</p>]]></description>
      <pubDate>Wed, 18 Jul 2007 09:36:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: Avaya Products PHP Multiple Vulnerabilities]]></title>
      <guid>http://www.phpdeveloper.org/news/8043</guid>
      <link>http://www.phpdeveloper.org/news/8043</link>
      <description><![CDATA[<p>
Secunia has <a href="http://secunia.com/advisories/25660/">posted a vulnerability</a> marked as "highly critical" for users of any of the Avaya products that use PHP:
</p>
<blockquote>
Avaya has acknowledged some vulnerabilities in various Avaya products, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions and potentially by malicious people to compromise a vulnerable system.
</blockquote>
<p>
The following products are affected:
</p>
<ul>
<li>Avaya Communication Manager (CM 4.0 and CM 2.x prior to load 127.0)
<li>Avaya CCS/SES (CCS/SES 3.1.1)
<li>Avaya AES (AES 4.0)
</ul>
<p>
Currently, according to <a href="http://support.avaya.com/elmodocs2/security/ASA-2007-231.htm">the original announcement</a> from Avaya, there are two issues that have been found and are able to be exploited - an issue with the xmlrpc extension and a problem with the ftp extension. Currently, there is no patch to correct these issues, but you can keep track of their current status via <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1864">their</a> <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2509">entries</a. on Avaya's tracking system.
</p>]]></description>
      <pubDate>Thu, 14 Jun 2007 08:02:00 -0500</pubDate>
    </item>
  </channel>
</rss>
