PHP 5.6.2 and 5.4.34 Update for Critical Security Flaws | Internet News

PHP 5.6.2 and 5.4.34 Update for Critical Security Flaws

Oct 20, 2014
1 minute read

While much of the security world is consumed with the latest branded vulnerability (last week it was POODLE), the open-source PHP programming language fixed some very serious bugs.php

PHP is widely deployed across the Internet and is the language used to power much of the world’s leading Content Management Systems (CMS) and blogs (including this one).

In the PHP 5.6.2 update, four security vulnerabilities are being fixed including: CVE-2014-3668, CVE-2014-3669 and CVE-2014-3670. Bug #68089 does not yet have a CVE number but it’s a non-trivial Null byte injection flaw.

PHP 5.4.34 is being patched for six vulnerabilities including CVE-2014-3668, CVE-2014-3669 and CVE-2014-3670. The non-CVE number issues include bug #66242, 67985, 68089 and 41631.

Across both PHP 5.4.x and PHP 5.6 updates, the CVE-2014-3669 is one of the most serious.

“An integer overflow flaw in PHP’s unserialize() function was reported, a Red Hat security advisory warns. “If unserialize() were used on untrusted data, this issue could lead to a crash or potentially information disclosure.”

Sean Michael Kerner is a senior editor at InternetNews.com. Follow him on Twitter @TechJournalist

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.