You are not logged in.

#1 2006-11-04 01:42:57

mhakali
Member
Registered: 2006-08-31
Posts: 31

[security] php 5.2.0 update (remote code execution)

Hi!

I just throw together an updated PHP package for those of you who want to patch your web servers against the advisory released yesterday.

The package is available here:

http://adiza.nexticom.net/files/package … pkg.tar.gz

The advisory is available here:

http://www.frsirt.com/english/advisories/2006/4317

Note that it is without IMAP and ODBC support since i did not have these packages installed.

Greets.

Offline

#2 2006-11-04 02:09:01

cactus
Taco Eater
From: t͈̫̹ͨa͖͕͎̱͈ͨ͆ć̥̖̝o̫̫̼s͈̭̱̞͍̃!̰
Registered: 2004-05-25
Posts: 4,622
Website

Re: [security] php 5.2.0 update (remote code execution)

mhakali. I applaud your attention to security.
However, it is generally not well received to post the same thing in multiple categories..

also, security advisories would probably be better served going into the Networking, Server, and Protection category.

Otherwise. thanks for the heads up.


"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍

Offline

#3 2006-11-04 02:11:50

mhakali
Member
Registered: 2006-08-31
Posts: 31

Re: [security] php 5.2.0 update (remote code execution)

tnx for the feedback, duely noted. smile

Offline

#4 2006-11-04 02:11:59

Snowman
Developer/Forum Fellow
From: Montreal, Canada
Registered: 2004-08-20
Posts: 5,212

Re: [security] php 5.2.0 update (remote code execution)

cactus wrote:

mhakali. I applaud your attention to security.
However, it is generally not well received to post the same thing in multiple categories..

Yes. Please do not cross-post: http://bbs.archlinux.org/viewtopic.php?p=205922
Use the above  thread for discussion.

Locking.

Offline

Board footer

Powered by FluxBB