Forumlar / Cotonti / General / Serious PHP security leak

ez
#1 2012-05-04 10:07

Apparently PHP has a serious leak which has not been patched YET.

Please check your own sites for this:

More info: http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/

Hopefully this will help somebody... :)

==- I say: Keep it EZ -==
Trustmaster
#2 2012-05-04 17:38

Thanks for sharing!

I generally avoid hosts running PHP in CGI mode and recommend others to do the same. Not just for security reasons, CGI mode works significantly slower than FastCGI or Apache module.

May the Source be with you!
Eugene
#3 2012-05-05 06:27

It would be great to list such (security) recommendations somewhere to make (at least) admins|developpers aware...