The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Running PHP on a Linux web server is a prerequisite for the use of many popular applications such as Wordpress, Joomla and Drupal. Linux administrators and web…
The Wiz research team has discovered a security issue in Azure App Service on Linux. This exposed the source code of client applications written in PHP, Python…
**PHP version 7.4.26** (18 Nov 2021) **Core:** * Fixed bug php#81518 (Header injection via default_mimetype / default_charset). (cmb) **Date:** * Fixed bug php…
**PHP version 7.4.26** (18 Nov 2021) **Core:** * Fixed bug php#81518 (Header injection via default_mimetype / default_charset). (cmb) **Date:** * Fixed bug php…
**PHP version 8.0.12** (21 Oct 2021) **CLI:** * Fixed bug php#81496 (Server logs incorrect request method). (lauri) **Core:** * Fixed bug php#81435 (Observer c…
Updated php packages fix security vulnerability: In PHP versions 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and…
**PHP version 7.4.25** (21 Oct 2021) **DOM:** * Fixed bug php#81433 (DOMElement::setIdAttribute() called twice may remove ID). (Viktor Volkov) **FFI:** * Fixed…
**PHP version 7.4.25** (21 Oct 2021) **DOM:** * Fixed bug php#81433 (DOMElement::setIdAttribute() called twice may remove ID). (Viktor Volkov) **FFI:** * Fixed…
PHP-PFM in PHP could be made to run program as an administrator if it received specially crafted input.
**PHP version 8.0.10** (26 Aug 2021) **Core:** * Fixed bug php#72595 (php_output_handler_append illegal write access). (cmb) * Fixed bug php#66719 (Weird behav…
**PHP version 7.4.23** (26 Aug 2021) **Core:** * Fixed bug php#72595 (php_output_handler_append illegal write access). (cmb) * Fixed bug php#66719 (Weird behav…
**PHP version 7.4.23** (26 Aug 2021) **Core:** * Fixed bug php#72595 (php_output_handler_append illegal write access). (cmb) * Fixed bug php#66719 (Weird behav…
Updated php-pear packages fix security vulnerability: In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive (CVE-2021-32…
An update for rh-php73-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Mod…
Updated php packages provides upstream 8.0.8 and fixes the following security vulnerabilities: - PDO_Firebird: * Fix Stack buffer overflow in firebird_info_cb …
The package php before version 8.0.8-1 is vulnerable to multiple issues including denial of service and insufficient validation.
**PHP version 7.4.21** (01 Jul 2021) **Core:** * Fixed bug php#81068 (Double free in realpath_cache_clean()). (Dimitry Andric) * Fixed bug php#76359 (open_base…
**PHP version 7.4.21** (01 Jul 2021) **Core:** * Fixed bug php#81068 (Double free in realpath_cache_clean()). (Dimitry Andric) * Fixed bug php#76359 (open_base…
Several security issues were fixed in PHP.
Updated PHP packages fix security vulnerabilities: - Fixed bug #81122: SSRF bypass in FILTER_VALIDATE_URL. (CVE-2021-21705) PDO_Firebird: - Fixed bug #76448: S…
**Version 6.5.0** (June 16th, 2021) * **SECURITY** Fixes **CVE-2021-34551**, a complex RCE affecting Windows hosts. See SECURITY.md for details. * The fix for …
**Version 6.5.0** (June 16th, 2021) * **SECURITY** Fixes **CVE-2021-34551**, a complex RCE affecting Windows hosts. See SECURITY.md for details. * The fix for …
Once again, the Magecart gang has made it to the news owing to a unique…Magecart Now Hides Malicious PHP Web Shells In Website Favicons on Latest Hacking News
**PHP version 7.4.19** (06 May 2021) **PDO_pgsql:** * Reverted bug fix for php#80892 (PDO::PARAM_INT is treated the same as PDO::PARAM_STR). (Matteo) ---- **PH…