#3203: PHP-5.3.4
----------------------------------------+-----------------------------------
Reporter: ra...@… | Owner: blfs-b...@…
Type: task | Status: new
Priority: high | Milestone: 6.7
Component: BOOK | Version: SVN
Severity: major | Keywords:
----------------------------------------+-----------------------------------
Changes (by ra...@…):
* owner: ra...@… => blfs-b...@…
* status: assigned => new
Old description:
> Version increment to 5.3.3
>
> http://us2.php.net/
>
> Quoted from the above URL:
> "The PHP development team would like to announce the immediate
> availability of PHP 5.3.3. This release focuses on improving the
> stability and security of the PHP 5.3.x branch with over 100 bug fixes,
> some of which are security related. All users are encouraged to upgrade
> to this release."
New description:
Version increment to 5.3.4
http://us2.php.net/
Quoted from the above URL:
{{{
Security Enhancements and Fixes in PHP 5.3.4:
* Fixed crash in zip extract method (possible CWE-170).
* Paths with NULL in them (foo\0bar.txt) are now considered as invalid
(CVE-2006-7243).
* Fixed a possible double free in imap extension (Identified by
Mateusz Kocielski). (CVE-2010-4150).
* Fixed NULL pointer dereference in ZipArchive::getArchiveComment.
(CVE-2010-3709).
* Fixed possible flaw in open_basedir (CVE-2010-3436).
* Fixed MOPS-2010-24, fix string validation. (CVE-2010-2950).
* Fixed symbolic resolution support when the target is a DFS share.
* Fixed bug #52929 (Segfault in filter_var with FILTER_VALIDATE_EMAIL
with large amount of data) (CVE-2010-3710).
}}}
--
Comment:
Updated BLFS to PHP-5.3.3. Since my installation, 5.3.4 has been released.
Both versions require additional dependencies (not listed in the 5.3.3
update as it will be short-lived).
{{{
http://www.geocities.jp/kosako3/oniguruma/
http://www.acme.com/software/thttpd/
http://pi3web.sourceforge.net/pi3web/
several non-free web-servers (probably not worth mentioning)
the "lemon" parser in the "tools" subdir of the SQLite tarball
}}}
--
Ticket URL: <http://wiki.linuxfromscratch.org/blfs/ticket/3203#comment:3>
BLFS Trac <http://wiki.linuxfromscratch.org/blfs>
Beyond Linux From Scratch
--
http://linuxfromscratch.org/mailman/listinfo/blfs-book
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page