-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUMMARY cPanel, Inc. has released EasyApache 3.28.4 with PHP versions 5.4.38 and 5.5.22. This release addresses vulnerabilities related to CVE-2015-0235 and CVE-2015-0273 by fixing bugs in the Core module. We strongly encourage all PHP 5.4 users to upgrade to version 5.4.38 and all PHP 5.5 users to upgrade to version 5.5.22. AFFECTED VERSIONS All versions of PHP 5.4 through version 5.4.37 All versions of PHP 5.5 through version 5.5.21. SECURITY RATING The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs: CVE-2015-0235 - HIGH PHP 5.4.38 Fixed bug in the Core module related to CVE-2015-0235 PHP 5.5.22 Fixed bug in the Core module related to CVE-2015-0235 CVE-2015-0273 - MEDIUM PHP 5.4.38 Fixed bug in the Core module related to CVE-2015-0273 PHP 5.5.22 Fixed bug in the Core module related to CVE-2015-0273 SOLUTION cPanel, Inc. has released EasyApache 3.28.4 with an updated version of PHP 5.4.38 and PHP 5.5.22. Unless you have disabled EasyApache updates, EasyApache updates automatically. Run EasyApache to rebuild your profile with the latest version of PHP. REFERENCES https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0235 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0273 http://php.net/ChangeLog-5.php -----BEGIN PGP SIGNATURE----- iQIcBAEBAgAGBQJU5571AAoJEJUhvtyr2U3fLXwP/jplWojQ88WoMuoGJuXKyN6s uNGF4hRUF82i35Ma6/tWjafnfp7DzEVgZpWqfDArG+0NBXW6FuZLfQKt43VDSe0b uCOBgSWk8dqKxfcz9JiWAtvK30E8kcwlM5onxWElCMpADuE/eRQjdcmseLMlo+oo LP68xcqpbzoVyjUJt2ktZ++BncyXZXn/kFYhd+7gY18q77JAxiJ7JTtliUa0a7LP w7URInMJUAVTf8EP3og9kwEVammJT4p0Umz4WTGXtEKbAWWTxjQVFlGzKXXJH63F VmNLGCgyiXWuz7iEFBx/DqAtKU9BgKkyw3VXbLuZg2/hr7nPruB+M6uvJHOSJOvD sld5M9YnJpU9/YY3qOq8osCe9R5IV1rlTOybwFYrtKNSayaIeorb+Nw/6DAJ4v9B DfEZEuMY4aREREnzfFL/TaBiIXT8quQ1vVYtO1vV4ThUokmpVX0PEhJNtucXEqAq Wk9ZK1xwTpxYupVxNCphx6Ez/3GyKS8lfOd9xJBYke441zYHu6oD0seDNQEpi6wa YXz3+0E8QOiN3qNvqmd0fG/cLARLBkYW+GrGTrzZKEijYYkOS/uUh5nxBWXQQQXM wNYLFCc9gvkolixKRklh+DmplepuT+Ht/b58gbhz12K0QCTpzYm4My2LltvDaOD5 C0KPnCgmfsww65xOl3gF =ECvh -----END PGP SIGNATURE-----