Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

February 3rd, 2012, 07:52 GMT · By Eduard Kovacs

BLOG

PHP 5.3.10 Released to Fix Remote Code Execution Flaw

SHARE:

Adjust text size:

Stefan Esser finds a major security bug in PHP Enlarge picture - Stefan Esser finds a major security bug in PHP
The security researcher and the developer of the Suhosin PHP Extension, Stefan Esser, found a serious arbitrary remote code execution vulnerability and reported it to the PHP Group. As a result, PHP 5.3.10 was released to address the issue.

It’s not certain if the older versions are affected, but the latest stable version is, H Security reports.

It turns out that the problem is caused by the security update to PHP 5.3.9 released to mitigate the denial of service attacks that rely on hash collisions. This was basically done by limiting the maximum possible number of input parameters to 1,000 in the max_input_vars variable.

However, the way this was implemented allows attackers to exceed the limit and remotely inject and execute arbitrary code over the web.

Esser recommends the use of Suhosin which “greately mitigates” and even “completely kills” the issue if user is in default configuration.

PHP 5.3.10
is available for download here.
FILED UNDER:
PHP
security update
Suhosin

TELL US WHAT YOU THINK:

829 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Mozilla Fixes Five Critical Vulnerabilities with Firefox 10

Counterclank Stays on Android Market, Symantec Gives More Explanations

Hundreds of WordPress Sites Compromised to Serve Phoenix Exploit Kit

Symantec Patches pcAnywhere, Customers Advised to Update

Drive-by Spam Emails Infect Computers Without Links or Attachments

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM