Auteur Sujet: [ThreatPost]PHP Group Releases New Versions, But Patch Doesn't Fix CVE-2012-1823 Bug  (Lu 4876 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
PHP Group Releases New Versions, But Patch Doesn't Fix CVE-2012-1823 Bug

<p><strong>UPDATE</strong>--The developers of PHP have released new versions of the scripting language to fix a <a href="https://threatpost.com/en_us/blogs/serious-remote-php-bug-accidentally-disclosed-050312?utm_source=Threatpost&amp;utm_medium=Tabs&amp;utm_campaign=Today%27s+Most+Popular">remotely exploitable vulnerability</a> announced earlier this week that enables an attacker to pass command-line arguments to the PHP binary. The flaw has been in the code for more than eight years and The PHP Group was working on a patch for it when the bug was disclosed accidentally on Reddit. However, the team that found the bug says the new versions of PHP don't actually fix the vulnerability.&nbsp;</p><p><a href="http://threatpost.com/en_us/blogs/php-group-releases-new-versions-patch-doesnt-fix-cve-2012-1823-bug-050412" target="_blank">read more</a></p>
Source: PHP Group Releases New Versions, But Patch Doesn't Fix CVE-2012-1823 Bug

Tags: