Blog

Security update to the script language "PHP" -Problems with the handling of zip archives

news

"PHP 8.0.11 "" PHP 7.4.24 "" PHP 7.3."31" is released

September 24, 2021 15:45

"PHP 8.0.11 "" PHP 7.4.24 "" PHP 7.3."31" is released

 The script language "PHP" was updated on September 23.Currently the official website "PHP.net」から"PHP 8.0.11 "" PHP 7.4.24 "" PHP 7.3."31" can be downloaded.Please note that it is a security update that has been modified vulnerabilities.

 The vulnerability (CVE-2021-21706) corrected this time is related to the handling of ZIP format documentary files.The implementation of "p_zip_make_relative_path ()" does not properly handle the absolute path of Windows (handles the path that starts with slash as an absolute path), so it is placed outside the output folder given by "Ziparchive :: EXTRACTTO ().It is said that files can be included in the ZIP archive.

 This problem seems to have existed for a long time, and the range of impact seems to be large.If you are dealing with ZIP archives in the old "PHP" version, you will need to update to the correction version.

スクリプト言語「PHP」にセキュリティアップデート ~ZIPアーカイブの扱いに問題

 In addition, in this version, the integer overflow when connecting the string and the heap overflow confirmed in "MSG_SEND" have been corrected.

Hot Articles

How to Save Websites as PDF on iPhone or PC | Business Insider Japan

How to Save Websites as PDF on iPhone or PC | Business Insider Japan

Sign up for a free e-mail newsletter We'll send you a Business Insider Japan e-mail newsletter at 17:00 on weekdays. Check the terms of use You can save the website as a PDF from various web browsers including Safari on iPhone. Photo: Takuma Imamura Web page suddenly ...

READ MORE READ MORE
Yahoo! News Digitalizing the traditional "small pattern dyeing" pattern Crisis of disappearance, challenge of long-established president

Yahoo! News Digitalizing the traditional "small pattern dyeing" pattern Crisis of disappearance, challenge of long-established president

In the file in front of Mr. Atsushi Tomita, a well-preserved paper pattern is included so that it is not exposed to the air as much as possible. To prepare for digitization and prevent deterioration = Taken by Hiroyuki Kondo on the morning of December 10, 2021 at Tomita Dyeing Crafts in Shinjuku-ku, Tokyo ...

READ MORE READ MORE
 It's okay if you forget to record the news!How to see the famous scenes of the Olympics later on your smartphone

It's okay if you forget to record the news!How to see the famous scenes of the Olympics later on your smartphone

Explaining how to use the archive distribution The Tokyo Olympics attracts attention not only for players' play but also for unique commentary. Even if you miss it even though it became a hot topic, or if you did not record it, you can do it at your favorite timing later ...

READ MORE READ MORE

Related Articles