Earlier quoted context omitted.
This is not a PHP language interpreter bug this is a PHP FPM bug.
That's a fair point, using 'interpreter' specifically was imprecise language on my part. My main point was php-fpm is developed by the core PHP team and is often the default in how PHP projects deploy these days, and that CVE was very similar to the recent 'fail' LPE vulnerabilities in the kernel.
CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
81–83 of 83 posts
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#82We've been running Centminmod on our servers for years. Love the software. There is no fancy web UI but it does have CLI menus, etc... so, definitely not for the novice but it's really good at what it does. I'm not affiliated, just a happy customer: https://centminmod.com/
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#83Ages ago I used php-nuke to manage my forum and it got hacked and I thought it would get taken seriously Seeing these CPanel hacks remind me how old these codebases are and how much more vulnerability remain
Cpanel is Perl, not PHP. Probably the grayest of the gray beards. Perhaps not enough Perl Wizards left to maintain it nowadays.
these cPanel machines frequently run 4- or low-5-figure quantities of customer accounts, each with potentially multiple domains or CMS deployments, and not always the most technically-engaged customer base, so that's a lot of surface area to account for: how diligent can hosts realistically be about every WordPress plugin, every Drupal or Magento module, and so on?
(nb I don't like shared hosting and am not defending it, just addressing the reality of the long tail)