PHP is an HTML-embedded scripting language. PHP attempts to make it
easy for developers to write dynamically generated web pages. PHP also
offers built-in database integration for several commercial and
non-commercial database management systems, so writing a
database-enabled webpage with PHP is fairly simple. The most common
use of PHP coding is probably as a replacement for CGI scripts.
The php package contains the module (often referred to as mod_php)
which adds support for the PHP language to Apache HTTP Server.
Update Information:
16 Apr 2015, **PHP 5.5.24**
Apache2handler:
* Fixed bug #69218 (potential remote code execution with apache 2.4 apache2handler). (Gerrit Venema)
Core: * Fixed bug #66609 (php crashes with __get() and ++ operator in some cases). (Dmitry, Laruence) * Fixed bug #67626 (User exceptions not properly handled in streams). (Julian) * Fixed bug #68021 (get_browser() browser_name_regex returns non-utf-8 characters). (Tjerk) * Fixed bug #68917 (parse_url fails on some partial urls). (Wei Dai) * Fixed bug #69134 (Per Directory Values overrides PHP_INI_SYSTEM configuration options). (Anatol Belski) * Additional fix for bug #69152 (Type confusion vulnerability in exception::getTraceAsString). (Stas) * Fixed bug #69212 (Leaking VIA_HANDLER func when exception thrown in __call/... arg passing). (Nikita) * Fixed bug #69221 (Segmentation fault when using a generator in combination with an Iterator). (Nikita) * Fixed bug #69337 (php_stream_url_wrap_http_ex() type-confusion vulnerability). ...
Read the Full Advisory* Wed Apr 15 2015 Remi Collet
[ 1 ] Bug #1185900 - CVE-2015-1351 php: use after free in opcache extension
https://bugzilla.redhat.com/show_bug.cgi?id=1185900
[ 2 ] Bug #1213411 - php: use-after-free vulnerability in php_curl related to CURLOPT_FILE/_INFILE/_WRITEHEADER
https://bugzilla.redhat.com/show_bug.cgi?id=1213411
[ 3 ] Bug #1213442 - php: denial of service when processing a crafted file with Fileinfo
https://bugzilla.redhat.com/show_bug.cgi?id=1213442
[ 4 ] Bug #1213449 - CVE-2015-3329 php: Buffer Over flow when parsing tar/zip/phar in phar_set_inode()
https://bugzilla.redhat.com/show_bug.cgi?id=1213449
[ 5 ] Bug #1185904 - CVE-2015-1352 php: NULL pointer dereference in pgsql extension
https://bugzilla.redhat.com/show_bug.cgi?id=1185904
[ 6 ] Bug #1213407 - php: missing null byte checks for paths in various PHP extensions
https://bugzilla.redhat.com/show_bug.cgi?id=1213407
[ 7 ] Bug #1213416 - php: NULL pointer dereference at ext/ereg/regex/reg...
This update can be installed with the "yum" update program. Use su -c 'yum update php' at the command line. For more information, refer to "Managing Software with yum", available at .
Get the latest Linux and open source security news straight to your inbox.