Description
The PHP development team would like to announce the immediate availability of PHP 5.2.6. This release focuses on improving the stability of the PHP 5.2.x branch with over 120 bug fixes, several of which are security related. All users of PHP are encouraged to upgrade to this release.
Security Enhancements and Fixes in PHP 5.2.6:
- Fixed possible stack buffer overflow in the FastCGI SAPI identified by Andrei Nigmatulin.
- Fixed integer overflow in printf() identified by Maksymilian Aciemowicz.
- Fixed security issue detailed in CVE-2008-0599 identified by Ryan Permeh.
- Fixed a safe_mode bypass in cURL identified by Maksymilian Arciemowicz.
- Properly address incomplete multibyte chars inside escapeshellcmd() identified by Stefan Esser.
- Upgraded bundled PCRE to version 7.6
Affected PHP versions (up to 5.2.5).
Remediation
Upgrade PHP to the latest version.
References
Related Vulnerabilities
Apache Traffic Server Improper Authentication Vulnerability (CVE-2021-38161)
WordPress Plugin Database for Contact Form 7, WPforms, Elementor forms Cross-Site Scripting (1.2.0)
WordPress Plugin PDW Media File Browser 'upload.php' Arbitrary File Upload (1.1)
Ruby on Rails CVE-2015-3227 Vulnerability (CVE-2015-3227)
Oracle Database Server CVE-2018-3004 Vulnerability (CVE-2018-3004)