The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A serious security vulnerability existed in the PHP Composer package. Exploiting this bug could allow…Vulnerability In PHP Composer Package Could Allow Supply-…
The maintainers of the PHP programming language have issued an update regarding the security incident that came to light late last month , stating that the act…
The maintainers of the PHP programming language have issued an update regarding the security incident that came to light late last month, stating that the acto…
Cyku Hong from DEVCORE discovered that php-nette, a PHP MVC framework, is vulnerable to a code injection attack by passing specially formed parameters to URL t…
This weekend's PHP hack serves as the latest reminder of the importance of server security- and the need to do better.
Unidentified attackers recently hacked the PHP Git server to inject the source code with a…Backdoor In PHP Source Code Discovered on Latest Hacking News
In PHP versions 7.2.x when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host …
**PHP version 7.3.23** (01 Oct 2020) **Core:** * Fixed bug php#80048 (Bug php#69100 has not been fixed for Windows). (cmb) * Fixed bug php#80049 (Memleak when …
**PHP version 7.4.11** (01 Oct 2020) **Core:** * Fixed bug php#79699 (PHP parses encoded cookie names so malicious `__Host-` cookies can be sent). (**CVE-2020-…
**PHP version 7.4.11** (01 Oct 2020) **Core:** * Fixed bug php#79699 (PHP parses encoded cookie names so malicious `__Host-` cookies can be sent). (**CVE-2020-…
A vulnerabilities in PHP could lead to a Denial of Service condition.
An update for the php:7.3 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of…
**PHP version 7.3.21** (06 Aug 2020) **Apache:** * Fixed bug php#79030 (Upgrade apache2handler's php_apache_sapi_get_request_time to return usec). (Herbert256)…
**PHP version 7.4.9** (06 Aug 2020) **Apache:** * Fixed bug php#79030 (Upgrade apache2handler's php_apache_sapi_get_request_time to return usec). (Herbert256) …
Updated php packages fix security vulnerabilities: - Fixed bug #78875 (Long filenames cause OOM and temp files are not cleaned). [1] - Fixed bug #78876 (Long v…
PHP could be made to crash if it received a specially crafted file.
**PHP version 7.3.18** (14 May 2020) **Core:** * Fixed bug php#78875 (Long filenames cause OOM and temp files are not cleaned). (**CVE-2019-11048**) (cmb) * Fi…
**PHP version 7.3.18** (14 May 2020) **Core:** * Fixed bug php#78875 (Long filenames cause OOM and temp files are not cleaned). (**CVE-2019-11048**) (cmb) * Fi…
**PHP version 7.4.6** (14 May 2020) **Core:** * Fixed bug php#78434 (Generator yields no items after valid() call). (Nikita) * Fixed bug php#79477 (casting obj…
**PHP version 7.3.17** (16 Apr 2020) **Core:** * Fixed bug php#79364 (When copy empty array, next key is unspecified). (cmb) * Fixed bug php#78210 (Invalid poi…
**PHP version 7.3.17** (16 Apr 2020) **Core:** * Fixed bug php#79364 (When copy empty array, next key is unspecified). (cmb) * Fixed bug php#78210 (Invalid poi…
Several security issues were fixed in PHP.
Multiple vulnerabilities have been found in PHP, the worst of which could result in the execution of arbitrary shell commands.
**PHP version 7.3.16** (19 Mar 2020) **Core:** * Fixed bug php#63206 (restore_error_handler does not restore previous errors mask). (Mark Plomer) **DOM:** * Fi…