Sept 10 2014: PHP vulnerability notification

Attention:

It was discovered that PHP did not properly handle certificates with NULLcharacters in the Subject Alternative Name field. An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications.

Notice:

We recommedn our affiliates connecting to us by PHP invoking HTTPS (SSL)  POST requests that they patch their systems accordingly.

For more information about which versions of linux bundles are affected please go to:

http://www.ubuntu.com/usn/usn-1937-1/

or

http://www.rapid7.com/db/vulnerabilities/ubuntu-USN-1937-1