Pay attention to multiple security vulnerabilities in PHP5.2.5 and earlier versions. Read the multiple security vulnerabilities in PHP5.2.5 and earlier versions. Release Date: updated:-11-13 affected systems: PHPPHP5.2.5 not affected systems: PHPPHP5.2.5 description: BUGTRAQID: 26403----CVE (CAN
Released on: 2007-11-08
Updated on: 2007-11-13
Affected systems:
PHP <5.2.5
Unaffected system:
PHP 5.2.5
Description:
Bugtraq id: 26403
---- CVE (CAN) ID: CVE-2007-4887
PHP is a widely used scripting language. it is especially suitable for Web development and can be embedded into HTML.
PHP versions earlier than 5.2.5 have multiple security vulnerabilities, including:
1) the htmlentities and htmlspecialchars functions do not accept partial multibyte sequences;
2) multiple buffer overflow exists in fnmatch (), setlocale (), and glob () functions;
3) processing errors in the. htaccess file may result in modifying the mail. force_extra_parameters php. ini command through the. htaccess file and bypassing the disable_functions Command;
4) an error in processing the variable may cause the ini_set () function to overwrite the value set in httpd. conf.
The current manufacturer has released a patch to fix this security problem, please download to the vendor's home page: http://www.php.net/get/php-5.2.5.tar.bz2/from/a/mirror