<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Sat, 18 May 2013 02:28:57 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[Secunia.com: SUSE update for php4 and php5]]></title>
      <guid>http://www.phpdeveloper.org/news/8240</guid>
      <link>http://www.phpdeveloper.org/news/8240</link>
      <description><![CDATA[<p>
As <a href="http://secunia.com/advisories/26048/">posted on Secunia.com today</a>, the SuSE linux distribution has release updates to both their PHP4 and PHP5 packages today:
</p>
<blockquote>
SUSE has issued an update for php4 and php5. This fixes some vulnerabilities, where one has an unknown impact and others can be exploited by malicious, local users to bypass certain security restrictions and gain escalated privileges, and by malicious people to to cause a DoS (Denial of Service), bypass certain security restrictions, and potentially compromise a vulnerable system.
</blockquote>
<p>
They have <a href="http://secunia.com/advisories/26048/">the update</a> marked as highly critical so it it suggested that users of SuSE upgrade immediately. The Secunia posting has links to all of the package downloads for each of the platform types and for multiple SuSE versions.
</p>]]></description>
      <pubDate>Fri, 13 Jul 2007 11:23:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: SUSE update for PHP4]]></title>
      <guid>http://www.phpdeveloper.org/news/8114</guid>
      <link>http://www.phpdeveloper.org/news/8114</link>
      <description><![CDATA[<p>
According to <a href="http://secunia.com/advisories/25816/">this new advisory</a> from Secunia today, the SuSE linux group has released a new package update for the PHP4 distribution on their operating system:
</p>
<blockquote>
SUSE has issued an update for php4. This fixes some vulnerabilities and a weakness, where one has an unknown impact and the others can be exploited by malicious, local users to gain escalated privileges, and by malicious, local users and malicious people to bypass certain security restrictions.
</blockquote>
<p>
The issue is marked as "Less critical" but it's still a good idea to update, especially when it relates to security issues. You can find more information at <a href="http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=http--supportnovellcom-techcenter-psdb-3e349d7efffdfecc96ca44f446d1b2c4html&sliceId=&dialogID=38853114&stateId=0%200%2038851668">the original advisory</a> on the Novell site.
</p>]]></description>
      <pubDate>Mon, 25 Jun 2007 09:17:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Secunia.com: SUSE update for PHP]]></title>
      <guid>http://www.phpdeveloper.org/news/7909</guid>
      <link>http://www.phpdeveloper.org/news/7909</link>
      <description><![CDATA[<p>
Secunia has release <a href="http://secunia.com/advisories/25056/">a new advisory</a> for SUSE linux users to point them to the update of the PHP packages on their system to correct a highly critical issue.
</p>
<blockquote>
SUSE has issued an update for php. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious people to disclose potentially sensitive information, to bypass certain security restrictions, to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.
</blockquote>
<p>
Operating systems included in the advisory are systems running SUSE Linux, UnitesLinux, and openSUSE linux. Package updates are linked <a href="http://secunia.com/advisories/25056/">from the advisory</a> so you can quickly and easily update your packages.
</p>]]></description>
      <pubDate>Wed, 23 May 2007 16:29:00 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[Net-Security.org: SUSE Security Announcement - php4,php5 problems]]></title>
      <guid>http://www.phpdeveloper.org/news/5605</guid>
      <link>http://www.phpdeveloper.org/news/5605</link>
      <description><![CDATA[<p>
In a new <a href="http://www.net-security.org/advisory.php?id=6388">SUSE security announcement</a> today, issues have been found with PHP4 and PHP5 bundled with serveral versions of their Linux operating system.
</p>
<p>
The four issues found are as follows:
<ul>
<li>Invalid characters in session names were not blocked.
<li>CVE-2006-2657: A bug in zend_hash_del() allowed attackers to prevent unsetting of some variables.
<li>CVE-2006-1991, CVE-2006-1990: Bugs in the substr_compare()  and wordwrap function could crash the php interpreter.
<li>CVE-2006-2906: A CPU consumption denial of service attack in php-gd was fixed.
</ul>
</p>
<p>
<a href="http://www.net-security.org/advisory.php?id=6388">These issues</a> affect the foloowing versions of SUSE: 10.1, 10.0, 9.3, 9.2, 9.1, Enterprise Server 8, SLES 9, and UnitedLinux 1.0. They can all be used to execute any arbitrary code the user chooses to inject. The severity level is higher on this one, but not at a critical level. It's still recommended, however, that you upgrade as soon as possible. Links to the various upgrade packages <a href="http://www.net-security.org/advisory.php?id=6388">can be found here</a>
</p>]]></description>
      <pubDate>Fri, 16 Jun 2006 06:14:29 -0500</pubDate>
    </item>
    <item>
      <title><![CDATA[PHP Magazine: SuSE - New PHP Packages Fix XSS and Information Leak]]></title>
      <guid>http://www.phpdeveloper.org/news/5337</guid>
      <link>http://www.phpdeveloper.org/news/5337</link>
      <description><![CDATA[<p>
The SuSE linux group has released new packages, according to <a href="http://www.php-mag.net/magphpde/magphpde_news/psecom,id,25731,nodeid,5.html">this post</a> on the PHP Magazine site, to deal with the XSS and information leak issues found recently in PHP4 and PHP5.
</p>
<quote>
<i>
A new update fixes security issues in the scripting languages PHP4 and PHP5 including a vulnerability in copy() and tempnam() functions that could bypass open_basedir restrictions, a cross-site-scripting (XSS) bug in phpinfo(), a vulnerability in mb_send_mail() that lacked safe_mode checks, and a bug in html_entity_decode() that could expose memory content. Fixed packages are available from <a href="ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/">ftp.suse.com</a>.
</i>
</quote>
<p>
It is strongly suggested that <a href="ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/">you upgrade your installation</a> to prevent any issues/problems from arrising.
</p>]]></description>
      <pubDate>Tue, 09 May 2006 06:30:34 -0500</pubDate>
    </item>
  </channel>
</rss>
