Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

January 13th, 2012, 08:13 GMT · By Eduard Kovacs

BLOG

PHP 5.3.9 Fixes Hash Collision Vulnerability

SHARE:

Adjust text size:

PHP 5.3.9 fixes a hash collision flaw Enlarge picture - PHP 5.3.9 fixes a hash collision flaw
After researchers showed how some programing language implementations and platforms were susceptible to hash collision attacks, PHP being among them, the PHP Group released PHP 5.3.9 which resolves the issue.

So far, the max_input_vars directive that mitigated hash collision attacks was present in PHP 5.4.0 RC4, but since this variant wasn’t stable, its use wasn’t a long-term solution.

Now, the max_input_vars is present in the 5.3.9 version which means that users who upgrade to this latest variant are protected against a potential attack.

Another fix that addresses a security issue refers to an integer overflow during the parsing of an invalid EXIF header. The bug could have allowed a hacker to launch a denial of service attack or read arbitrary memory.

This weakness only affected the 32 bit version.

PHP 5.3.9 / 5.4 RC5 is available for download here.

TELL US WHAT YOU THINK:

1,040 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Adobe Releases Security Update for Acrobat and Reader X

Microsoft Releases Security Update, Patches the BEAST Flaw in SSL/TLS

Chrome 16.0.912.75 Stable Fixes High-Priority Vulnerabilities

Protect Your HP LaserJet Devices with the Latest Firmware, Download Here

WordPress 3.3.1 Released to Fix XSS Vulnerability

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM