Koozali.org: home of the SME Server

Vulnerabilities in PHP

Anonymous

Vulnerabilities in PHP
« on: July 19, 2004, 10:43:12 AM »
Dear all,

Recent reports have learned that there are several serious security related bugs found in PHP version 4.3.7 and lower and 5.0.0CR3.

The vulnerabilities are:
- PHP memory_limit vulnerability
- PHP "Strip_tags()" vulnerability

Both vulnerabilites allow to run malicious code, when exploited.

Is this going to be fixed by upgrading PHP?? Is there already an upgrade package available??

Regards,
Peter