Zend - The PHP Company


Announcing the release of Zend Server 5.6 Hotfix 2

This hotfix resolves a critical security vulnerability found in the versions of PHP included in Zend Server 5.6.0 for Linux, Windows, and Macintosh (for both PHP 5.3 and PHP 5.2).  The exploit (CVE-2012-0830) could allow arbitrary code to be remotely executed on a PHP system.

Zend Server and Zend Server CE 5.6.0 users for Windows or Linux should apply the hotfix immediately:

  • Linux: run your package manager's update command (see the Zend Server Installation Guide for more details)
  • Windows: download Hotfix 2
  • Mac OS: Hotfix 2 is being finalized and will be available next week (Note – Zend Server is not supported for production use on Mac OS)
  • IBM i systems running Zend Server 5.6.0 are not vulnerable to this exploit
  • Previous versions of Zend Server are not vulnerable to this exploit