2019å¹´10æ25æ¥(æ¥æ¬æé)ãPHPéçºãã¼ã ã¯PHP 7.1ã7.2ã7.3 ã«ããã¦èå¼±æ§ (CVE-2019-11043) ãä¿®æ£ãããã¼ã¸ã§ã³ãå ¬éãã¾ããã æ¬èå¼±æ§ã¯ãnginx 㨠PHP-FPM ãçµã¿åãããç°å¢ã«ããã¦ä»¥ä¸ã®ãããªè¨å®ãããã¦ããå ´åã«ããªã¢ã¼ãã³ãã³ãå®è¡ãå¯è½ã«ãªãã¨ãããã®ã§ãã location ~ [^/]\.php(/|$) { fastcgi_split_path_info ^(.+?\.php)(/.*)$; fastcgi_param PATH_INFO $fastcgi_path_info; fastcgi_pass php:9000; ... } nginxå´ã®å¦çã«ã¦URLã«æ¹è¡ã³ã¼ã(%0a, %0d)ãå«ã¾ããéã®ä¸åã«èµ·å ããæ»æè ã¯ç´°å·¥ããæªæã®ãããªã¯ã¨ã¹ãããµã¼ãã«éããã¨ã§ãæ¬èå¼±æ§ãæªç¨ãã¦PHPã®ä»»æã®è¨å®
{{#tags}}- {{label}}
{{/tags}}