Форумы / Cotonti / General / Serious PHP security leak

ez
#1 04.05.2012 10:07

Apparently PHP has a serious leak which has not been patched YET.

Please check your own sites for this:

More info: http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/

Hopefully this will help somebody... :)

==- I say: Keep it EZ -==
Trustmaster
#2 04.05.2012 17:38

Thanks for sharing!

I generally avoid hosts running PHP in CGI mode and recommend others to do the same. Not just for security reasons, CGI mode works significantly slower than FastCGI or Apache module.

May the Source be with you!
Eugene
#3 05.05.2012 06:27

It would be great to list such (security) recommendations somewhere to make (at least) admins|developpers aware...