Hello e-smith,

  Just when you thought you were finished upgrading the webserver,
  'The PHP Group has learned of a serious security vulnerability in
  PHP versions 4.2.0 and 4.2.1. An intruder may be able to execute
  arbitrary code with the privileges of the web server. This
  vulnerability may be exploited to compromise the web server and,
  under certain conditions, to gain privileged access.' Here's the
  bugtraq announcement." The hole is in the parsing of HTTP POST headers and
  can allow arbitrary code to be run on vulnerable machines. PHP thoughtfully
  decided to release a new version, 4.2.2, today with the fix.

  http://online.securityfocus.com/archive/1/283533/2002-07-19/2002-07-25/0

  http://www.php.net/downloads.php
-- 
Regards,
 Haj
 [EMAIL PROTECTED]


--
Please report bugs to [EMAIL PROTECTED]
Please mail [EMAIL PROTECTED] (only) to discuss security issues
Support for registered customers and partners to [EMAIL PROTECTED]
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]
Archives by mail and http://www.mail-archive.com/devinfo%40lists.e-smith.org

Reply via email to