Tenon Intersystems Please see text links at bottom of page for navigation
Please see text links at bottom of page for navigation

Search tenon.com

Thanks to:

iTools

Re: PHP vulnerability

To: itools@xxxxxxxxxxxxxxx
Subject: Re: PHP vulnerability
From: anita@xxxxxxxxx (Anita Holmgren)
Date: Thu, 28 Feb 2002 09:55:19 -0800
At 10:00 AM +0000 2/28/02, Keith Beeby wrote:
Hi,

Any idea how quickly Tenon will have v4.1.2 ready?

This advisory was posted yesterday. We should have an update on Monday. Thanks for posting this.


-Anita


Until then the only option is to:


Disable fileuploads

If upgrading is not possible or a patch cannot be applied, you can avoid
these vulnerabilities by disabling fileupload support. Edit the PHP
configuration file php.ini as follows:

file_uploads = off
Note that this setting only applies to version 4.0.3 and above. However,
this will prevent you from using fileuploads, which may not be acceptable in
your environment.

See http://www.cert.org/advisories/CA-2002-05.html for more details,


Regards,


Keith

-- Tenon Intersystems 805-963-6983 1123 Chapala Street anita@xxxxxxxxx Santa Barbara, CA 93101 http://www.tenon.com

<Prev in Thread] Current Thread [Next in Thread>

| Tenon Home | Products | Order | Contact Us | About Tenon | Register | Tech Support | Resources | Press Room | Mailing Lists |

Powered By iTools

Copyright©2003 Tenon Intersystems, 232 Anacapa Street, Suite 2A, Santa Barbara, CA 93101. All rights reserved.
Questions about our website - Contact: webmaster@tenon.com.


Tenon Home  Tenon Home  Tenon Home  Tenon Home Product Info  Tenon Ordering Contact About Register Support Resources Press Mailing Lists