-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 SUMMARY cPanel, Inc. has released EasyApache 3.32.0 with PHP versions 5.4.45, 5.5.29, and 5.6.13. This release addresses vulnerabilities related to CVE-2105-6834, CVE-2015-6835, CVE-2015-6836, CVE-2015-6837, and CVE-2015-6838. We strongly encourage all PHP 5.4 users to upgrade to version 5.4.45, all PHP 5.5 users to upgrade to version 5.5.29, and all PHP 5.6 users to upgrade to version 5.6.13. AFFECTED VERSIONS All versions of PHP 5.4 through version 5.4.44 All versions of PHP 5.5 through version 5.5.28 All versions of PHP 5.6 through version 5.6.12 SECURITY RATING The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs: CVE-2015-6834 - MEDIUM PHP 6.4.45 Fixed bug in core and SPL related to CVE-2015-6834 PHP 6.5.29 Fixed bug in core and SPL related to CVE-2015-6834 PHP 6.6.13 Fixed bug in core and SPL related to CVE-2015-6834 CVE-2015-6835 - MEDIUM PHP 6.4.45 Fixed bug in core related to CVE-2015-6835 PHP 6.5.29 Fixed bug in core related to CVE-2015-6835 PHP 6.6.13 Fixed bug in core related to CVE-2015-6835 CVE-2015-6836 - MEDIUM PHP 6.4.45 Fixed bug in SOAP extension related to CVE-2015-6836 PHP 6.5.29 Fixed bug in SOAP extension related to CVE-2015-6836 PHP 6.6.13 Fixed bug in SOAP extension related to CVE-2015-6836 CVE-2015-6837 - MEDIUM PHP 6.4.45 Fixed bug in XSLT related to CVE-2015-6837 PHP 6.5.29 Fixed bug in XSLT related to CVE-2015-6837 PHP 6.6.13 Fixed bug in XSLT related to CVE-2015-6837 CVE-2015-6838 - MEDIUM PHP 6.4.45 Fixed bug in XSLT related to CVE-2015-6838 PHP 6.5.29 Fixed bug in XSLT related to CVE-2015-6838 PHP 6.6.13 Fixed bug in XSLT related to CVE-2015-6838 SOLUTION cPanel, Inc. has released EasyApache 3.32.0 with updated versions of PHP 5.4.45, 5.5.29, and 5.6.13. Unless you have disabled EasyApache updates, the EasyApache application updates to the latest version when launched. Run EasyApache to rebuild your profile with the latest version of PHP. REFERENCES https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-6834 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-6835 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-6836 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-6837 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-6838 http://php.net/ChangeLog-5.php -----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iQIcBAEBCgAGBQJV8IRdAAoJEJUhvtyr2U3fC2oP/ilelgpQE1/6AFdxBXmRw0ol OtBF25cLipkyxkjE/Nho+zBb35QqzQLVdxPuqNHvlAR8mwvJJmGpFEqqg+qxbcKG 2b+AMwktpEXqpeFhLLk081USIllHggILICkcGjoVm9XOZksffuoU0nmahz1CkgKZ dzFfsW4OAkhGsr6kspDvq2BUFuC07WHR/GtEv1ea6PtKyODqhsfPJ1wma+J1IeUP yduAc8sXJ+pfZKRn1HWyncESFQSM2MSyjbkjXAuYB/rHKISxES+Pas9DPcvw3/Fa wRoa/UXLLb12WMDnjm8/cywhGaWb470eH0MeoX123OpiKzqRKnC04xUIIHHmtRuE JlMgEzSd1QP1orEm9QNRZd+LMerpY2K3S768K7tAsH7EekQwVvW9cY6kiify/his f6P43vSbLrKVVxsJ3dTBOeEV8FiSjFAJLfRhMGTAIrofY/fnWntRSXIhJUl0AQ9j 8+m/UMMgh7fw3ypf2TZ/gQTiOpOCUzMea7fjvkkWPaWHi1TPYwADi8OzLTdkGQMC ZAToVVHdpCTJzeDv4NuoG+4rh0dtNKbV4XqpGttrWdJbpco0YZahedpzCeUBpdXB VmOVt+zxg2VQgpyqwsuzMxBvocnJp6rOk/fXc/wDxKT17P7qD5e94GZpt/D8h9+H 6WTxQDh0C1sjXam2HIPL =XfmH -----END PGP SIGNATURE-----