-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 SUMMARY cPanel, Inc. has updated RPMs for EasyApache 4 with PHP versions 5.6.33, 7.0.27, 7.1.13, and 7.2.1 and released EasyApache 3.34.20 with PHP version 5.6.33 on January 9, 2018. This release addresses vulnerabilities related to CVE-2015-8866. We strongly encourage all PHP 5.6 users to upgrade to versions 5.6.33, all PHP 7.0 users to upgrade to version 7.0.27, all PHP 7.1 users to upgrade to version 7.1.13, and all PHP 7.2 users to upgrade to version 7.2.1. AFFECTED VERSIONS All versions of PHP 5.6 through 5.6.32 All versions of PHP 7.0 through 7.0.26 All versions of PHP 7.1 through 7.1.12 All versions of PHP 7.2 through 7.2.0 SECURITY RATING The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs: CVE-2015-8866 - HIGH PHP 7.0.27 Fixed bug in LibXML related to CVE-2015-8866 PHP 7.1.13 Fixed bug in LibXML related to CVE-2015-8866 PHP 7.2.1 Fixed bug in LibXML related to CVE-2015-8866 Additional CVEs fixed but not assigned numbers yet for: The GD extension for PHP 5.6.33, 7.0.27, 7.1.13, and 7.2.0 The Phar extension for PHP 5.6.33, 7.0.27, 7.1.13. and 7.2.0 SOLUTION cPanel, Inc. has released updated RPMs for EasyApache 4 on January 9, 2018, with a updated versions of PHP versions 5.6.33, 7.0.27, 7.1.13, and 7.2.1. Unless you have enabled automatic RPM updates in your cron, update your system with either yum update or WHM's Run System Update interface. cPanel, Inc. has released EasyApache 3.34.20 with an updated versions of PHP 5.6.33. Unless you have disabled EasyApache updates, the EasyApache application updates to the latest version when launched. Run EasyApache to rebuild your profile with the latest version of PHP. REFERENCES https://nvd.nist.gov/vuln/detail/CVE-2015-8866 http://www.php.net/ChangeLog-5.php http://www.php.net/ChangeLog-7.php -----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iQIzBAEBCgAdFiEEtnCbTMb0IHf2mEGRlSG+3KvZTd8FAlpVFkoACgkQlSG+3KvZ Td+ZSA/+JpeFtGSmqYHD3L2mr67JQQZLaKSaxgMEv5aO6UvpuIf9REOFSy2Z50JD bx2g+dnKIwPD3+zkMG78f1Dm6/VR1SXdxpR/ZK5Ywcs2dHElZOpEwuTSz5gbkIZ3 1XNcc8l+mX8eLC2CT4RKX6aXh/NZCb1/5AKCJdItJEE+XkqYnxOMjj9pZvjbJEv0 5w8EkzrQWaA4HQXciwpQnpO2TKg9XgDo2woR8LR/M9Ul+1L4rIxzCBH7FehL8pQR CLHPTv/gNtPH5fwtMu6LOtz/u8SwIhUrqZdE+eNgU8aMDolOjw2WYcOoc9jY7/Zv o4KDIkr1AEhYEoQlvpNaFWBJBrhCzaNY/LyW/rnegjGCyrpE+M30dgzAMnZGi8BB xYm/mkvxUuWh50aHJwhx6xS6YSQLziUHVEzKxRmNtki0vPa585v97qY4GQL8k2Ta ForHv0B3j4fHaaP52XFgSh8uJTuTHVkgXhSWfWIKVVR0B6c0DhzEl+P9KwYSg5FH wpY/OMAmEKUMlOBpj4km6WctKI6OqZBX53EEsQZSYNlLwo7+vyqVAoSJQvpUyDE1 HJXpm/DgIKZHmql1T1FvhFb91u5nL5ThEyOZcCKNmxhBaWsCCbBLqe7U0/5Baq0h LD9HYyQKsUXq6VgUd+Vess4+B9SIC38pfZJHq4wXvm9GLgkV9m4= =UpJ3 -----END PGP SIGNATURE-----