Announcing the release of Zend Server 5.6 Hotfix 2
This hotfix resolves a critical security vulnerability found in the versions of PHP included in Zend Server 5.6.0 for Linux, Windows, and Macintosh (for both PHP 5.3 and PHP 5.2). The exploit (CVE-2012-0830) could allow arbitrary code to be remotely executed on a PHP system.Zend Server and Zend Server CE 5.6.0 users for Windows or Linux should apply the hotfix immediately:
- Linux: run your package manager's update command (see the Zend Server Installation Guide for more details)
- Windows: download Hotfix 2
- Mac OS: Hotfix 2 is being finalized and will be available next week (Note – Zend Server is not supported for production use on Mac OS)
- IBM i systems running Zend Server 5.6.0 are not vulnerable to this exploit
- Previous versions of Zend Server are not vulnerable to this exploit

