Php: Cross-site Scripting (XSS) Vulnerability

Users of php please be advised of a Cross-site Scripting vulnerability that has been identified.
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (

MDVSA-2010:224: [MDVSA-2010:224] php Cross-site Scripting
Problem Description:

A vulnerability was discovered and corrected in php:

A flaw in ext/xml/xml.c could cause a cross-site scripting (XSS)

vulnerability (CVE-2010-3870).

Packages for 2009.0 are provided as of the Extended Maintenance

Program. Please visit this link to learn more:

The updated packages have been patched to correct these issues.