Administrator Posted June 30, 2014 Posted June 30, 2014 SUMMARYcPanel, Inc. has released EasyApache 3.24.22 with PHP 5.4.30 and 5.5.14. This release addresses multiple PHP vulnerabilities in the PHP core code and the Fileinfo, Network, and SPL modules. We encourage all PHP users to upgrade to PHP 5.4.30 and PHP 5.5.14. AFFECTED VERSIONSAll versions of PHP 5.4 before 5.4.30.All versions of PHP 5.5 before 5.5.14. SECURITY RATINGThe National Vulnerability Database (NIST) has given the following severity ratings to these CVEs: CVE-2014-3981 – LOW PHP 5.4.30 and PHP 5.5.14Fixed bug in the PHP core code related to CVE-2014-3981. CVE-2014-0207 – MEDIUM PHP 5.4.30 and PHP 5.5.14Fixed bug in the Fileinfo module related to CVE-2014-0207. CVE-2014-3478 – MEDIUM PHP 5.4.30 and PHP 5.5.14Fixed bug in the Fileinfo module related to CVE-2014-3478. CVE-2014-3479 – MEDIUM PHP 5.4.30 and PHP 5.5.14Fixed bug in the Fileinfo module related to CVE-2014-3479. CVE-2014-3480 – MEDIUM PHP 5.4.30 and PHP 5.5.14Fixed bug in the Fileinfo module related to CVE-2014-3480. CVE-2014-3487 – MEDIUM PHP 5.4.30 and PHP 5.5.14Fixed bug in the Fileinfo module related to CVE-2014-3487. CVE-2014-4049 – MEDIUM PHP 5.4.30 and PHP 5.5.14Fixed bug in the Network module related to CVE-2014-4049. CVE-2014-3515 – MEDIUM PHP 5.4.30 and PHP 5.5.14Fixed bug in the SPL module related to CVE-2014-3515. SOLUTIONcPanel, Inc. has released EasyApache 3.24.22 with an updated version of PHP 5.4 and PHP 5.5 to correct this issue. Unless you have disabled EasyApache updates, EasyApache updates automatically. Run EasyApache to rebuild your profile with the latest version of PHP. REFERENCEShttp://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3981http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0207http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3478http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3479http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3480http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3487http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-4049http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3515http://www.php.net/ChangeLog-5.php#5.4.30http://www.php.net/ChangeLog-5.php#5.5.14 For the PGP-signed message, see PHP 5-4-30 and 5-5-14 CVE signed. View the full article
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now