store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Tue May 21, 2013 7:47 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 6 posts ] 
Author Message
 Post subject: PHP 5.3.13 and 5.4.3 released
Unread postPosted: Tue May 08, 2012 6:17 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
Quote:
The releases complete a fix for a vulnerability in CGI-based setups (CVE-2012-2311). Note: mod_php and php-fpm are not vulnerable to this attack.

PHP 5.4.3 fixes a buffer overflow vulnerability in the apache_request_headers() (CVE-2012-2329). The PHP 5.3 series is not vulnerable to this issue.


http://www.php.net/archive/2012.php#id2012-05-08-1

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: PHP 5.3.13 and 5.4.3 released
Unread postPosted: Tue May 08, 2012 6:25 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Quote:
PHP 5.4.3 fixes a buffer overflow vulnerability in the apache_request_headers() (CVE-2012-2329). The PHP 5.3 series is not vulnerable to this issue.


ASL systems running the ASL kernel are immune to this vulnerability.

Quote:
The releases complete a fix for a vulnerability in CGI-based setups (CVE-2012-2311). Note: mod_php and php-fpm are not vulnerable to this attack.


As previously noted, ASL systems and real time rules users are immune to this vulnerability.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: PHP 5.3.13 and 5.4.3 released
Unread postPosted: Thu May 10, 2012 5:33 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
PHP 5.3.13 is currently up in Atomic, but the latest php-eaccelerator is for 5.3.12, which causes yum to do strange suggestions like installing a bunch of 32-bit packages on a 64-bit system.

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: PHP 5.3.13 and 5.4.3 released
Unread postPosted: Thu May 10, 2012 10:12 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
Yum can be amazingly dumb sometimes, yet brilliantly "smart" at others.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: PHP 5.3.13 and 5.4.3 released
Unread postPosted: Thu May 10, 2012 12:35 pm 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
breun wrote:
PHP 5.3.13 is currently up in Atomic, but the latest php-eaccelerator is for 5.3.12, which causes yum to do strange suggestions like installing a bunch of 32-bit packages on a 64-bit system.


Yeah, that's a pain!


Top
 Profile  
 
 Post subject: Re: PHP 5.3.13 and 5.4.3 released
Unread postPosted: Thu May 10, 2012 12:58 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
Well, I understand why yum is suggesting it, but it's definitely not what I want. :)

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 6 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group