Security-X
Forum Security-X => News => Discussion démarrée par: igor51 le mai 07, 2012, 17:07:16
-
PHP Group Releases New Versions, But Patch Doesn't Fix CVE-2012-1823 Bug
<p><strong>UPDATE</strong>--The developers of PHP have released new versions of the scripting language to fix a <a href="https://threatpost.com/en_us/blogs/serious-remote-php-bug-accidentally-disclosed-050312?utm_source=Threatpost&utm_medium=Tabs&utm_campaign=Today%27s+Most+Popular">remotely exploitable vulnerability</a> announced earlier this week that enables an attacker to pass command-line arguments to the PHP binary. The flaw has been in the code for more than eight years and The PHP Group was working on a patch for it when the bug was disclosed accidentally on Reddit. However, the team that found the bug says the new versions of PHP don't actually fix the vulnerability. </p><p><a href="http://threatpost.com/en_us/blogs/php-group-releases-new-versions-patch-doesnt-fix-cve-2012-1823-bug-050412" target="_blank">read more</a></p>
Source: PHP Group Releases New Versions, But Patch Doesn't Fix CVE-2012-1823 Bug (http://threatpost.com/en_us/blogs/php-group-releases-new-versions-patch-doesnt-fix-cve-2012-1823-bug-050412)