[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kolab-users
Subject:    RE: [Kolab-devel] Supercolliding a PHP array - DoS Attacks
From:       "ABBAS Alain" <alain.abbas () libertech ! fr>
Date:       2012-01-09 22:49:52
Message-ID: 20120109224952.55992hee77nug084 () kolab ! libertech ! fr
[Download RAW message or body]




-----Message original-----
De: "ABBAS Alain" <alain.abbas@libertech.fr>
Envoyé: 9 janvier 2012 22:48:02 UTC
A: kolab-users@kolab.org
Cc: kolab-devel@kolab.org
Sujet : [Kolab-devel] Supercolliding a PHP array - DoS Attacks

Hello

There are a serious Dos Attack issue in PHP prior to 5.3.9

This attack is more than easy and serious. 
PHP 5.3.9 has a change to prevent this DoS attack. Microsoft's also has this issue which MS and made an
emergency patch available last week  to fix this.

see the links

http://nikic.github.com/2011/12/28/Supercolliding-a-PHP-array.html
http://cryptanalysis.eu/blog/2011/12/28/effective-dos-attacks-against-web-application-plattforms-hashdos/
http://williamedwardscoder.tumblr.com/post/14939418095/hash-table-attacks-impervious-hash-tables

oops typo 
does Kolab.org plan to give an update of php for this security issue? 

Regards

_______________________________________________
Kolab-devel mailing list
Kolab-devel@kolab.org
https://kolab.org/mailman/listinfo/kolab-devel

_______________________________________________
Kolab-users mailing list
Kolab-users@kolab.org
https://kolab.org/mailman/listinfo/kolab-users

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic