The PHP has released new versions to fix three security vulnerabilities, one of which is said to be critical and leads to remote code execution.
The vulnerability “CVE-2014-3669” can cause an “overflow” when accessing specially crafted serialized data with unserialize() . The vulnerability is only a 32-bit system, but the risk is caused by the violation and the data sequence often comes from user-controlled channels.
In addition, the updates have fixed bugs related to the introduction of a null byte in the cURL library, causing a dynamic memory corruption during the processing of modified data as a function of exif_thumbnail(), in image processing (CVE-2014-3670), as well as an overflow in the mkgmtime() function from the XMLRPC module (CVE-2014-3668).
These vulnerabilities were discovered by the IT Research Lab of security firm High-Tech Bridge. The new versions 5.6.2, 5.5.18 and 5.4.34 address these three vulnerabilities.
