The PHP development group has officially release the latest update for the stable PHP 5.4.x line - PHP 5.4.28.
The PHP development team announces the immediate availability of PHP 5.4.28. 19 bugs were fixed in this release, including CVE-2014-0185. All PHP 5.4 users are encouraged to upgrade to this version.
The CVE fix involves an issue around a PHP-FPM bug that could allow for privilege escalation due to default permissions. Users of previous releases in the PHP 5.4.x series and PHP-FPM are strongly encouraged to update to this latest release. You can download this release from the main downloads page (Windows users go here.