Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

From the CVE:

> Solution

> On October 24, PHP 7.3.11 (current stable) and PHP 7.2.24 (old stable) were released to address this vulnerability along with other scheduled bug fixes. Those using nginx with PHP-FPM are encouraged to upgrade to a patched version as soon as possible.

> If patching is not feasible, the suggested workaround is to include checks to verify whether or not a file exists. This is achieved either by including the try_files directive or using an if statement, such as if (-f $uri).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: