Foren / Cotonti / General / Serious PHP security leak

ez
#1 4. Mai 2012, 10:07

Apparently PHP has a serious leak which has not been patched YET.

Please check your own sites for this:

More info: http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/

Hopefully this will help somebody... :)

==- I say: Keep it EZ -==
Trustmaster
#2 4. Mai 2012, 17:38

Thanks for sharing!

I generally avoid hosts running PHP in CGI mode and recommend others to do the same. Not just for security reasons, CGI mode works significantly slower than FastCGI or Apache module.

May the Source be with you!
Eugene
#3 5. Mai 2012, 06:27

It would be great to list such (security) recommendations somewhere to make (at least) admins|developpers aware...