Most Popular in Linux
-
Tizen 1.0 hands-on: Can Samsung and Intel?s mobile OS compete with Android?
-
Two EA Games Arrive in Ubuntu 12.04 LTS
-
Obama calls Romney auto bailout claim an 'Etch-a-Sketch moment'
-
Olympia torch lighting starts London countdown
-
Fedora Project is naming names
-
Moderate Taliban says majority of group wants peace
-
How to Sync Files to Amazon S3 on Linux
-
Firefox 4 Beta Brings Speed Boost
-
Development Release: GNOME 4.0 Beta
-
Romney faces lengthy to-do list as likely GOP pick
Critical PHP vulnerability being fixed (The H)
The H is reporting that a critical remote code execution bug has been found in PHP that was caused by the recent fix for the widespread denial of service via hash collisions vulnerability. "The cause of the problem is the security update to PHP 5.3.9, which was written to prevent denial of service (DoS) attacks using hash collisions. To do so, the developers limited the maximum possible number of input parameters to 1,000 in php_variables.c using max_input_vars. Because of mistakes in the implementation, hackers can intentionally exceed this limit and inject and execute code. The bug is considered to be critical as code can be remotely injected over the web."
More Stories in Linux Weekly News
- Stable kernels 3.0.32 and 3.3.7
- Nmap 6 released
- Linux kernel 3.2.18 released
- The Russians Are Coming: A First Look At Rosa 2012 Marathon (O'Reilly)
- Perl 5.16.0 released
- The 3.4 kernel is out
- X.Org: "A Wasteland of Unreviewedness" (Phoronix)
- A scientific basis for Open Source Software
- Security advisories for Friday
- Fedora 17 release pushed back to May 29
Most Popular Stories
A fix for those "Pairing Record Missing" errors
Splitting the file
AIX KSH: 0403-029 There is not enough memory available now
sed substitution for specific record
You're the Pundit: Are we going to see form factor changes?
Earthlapse is a window on the Earth from space
Lulzlover Hacked Coalition of Law Enforcement, Data Dumped for 2,400 Cops & Feds
Rumored three iPad model lineup could cut entry price to $299
AIRbudz: A safer way to listen to your tunes
sendmail long text