[Modsecurity] How to prevent PHP 4.4.x/5.x Vulnerabilities

Steve West stevewest15 at gmail.com
Tue Apr 18 19:53:26 EDT 2006


Hi folks,

I'm wondering if anyon knows how to prevent some PHP 4.4.x/5.x
vulnerabilities via mod_security until PHP group releases fixes for
these. Here is more info on the vulnerabilities:

PHP copy() function: http://securitytracker.com/alerts/2006/Apr/1015882.html

PHP tempname() Arg: http://securitytracker.com/alerts/2006/Apr/1015881.html

PHP crashing Apache: http://securitytracker.com/alerts/2006/Apr/1015880.html

PHP phpinfo() validation:
http://securitytracker.com/alerts/2006/Apr/1015879.html

Thanks,

SW


More information about the Modsecurity mailing list