Bug#537788: [php-maint] Bug#537788: php5 + suhosin with suhosin.session.encrypt = On segfaults

2009-08-30 Thread Stefan Bühler
seems to be gone with latest updates (5.2.10.dfsg.1-2.1), 
suhosin.session.encrypt can be turned on again



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#537788: [php-maint] Bug#537788: php5 + suhosin with suhosin.session.encrypt = On segfaults

2009-07-25 Thread Stefan Bühler
Jan Wagner w...@cyconet.org wrote:
 Hi,

 Do you have any steps to reproduce the issue? Possible any scripts or
 anything?


See attachment.
attachment: test.php


Bug#537788: [php-maint] Bug#537788: php5 + suhosin with suhosin.session.encrypt = On segfaults

2009-07-25 Thread Jan Wagner
Hi Stefan,

On Saturday 25 July 2009, Stefan Bühler wrote:
 Jan Wagner w...@cyconet.org wrote:
  Hi,
 
  Do you have any steps to reproduce the issue? Possible any scripts or
  anything?

 See attachment.

I can confirm your problem on sid (i386), even with libapache2-mod-fcgid. The 
problem is unfortunatly, installing php5 from testing (php5-suhosin still from 
unstable) solves that problem. So this is an issue of php5, like the gentoo 
bugtracker indicated.

Installing the php5 from testing worked for me with (testing source-line 
required):

 aptitude install php5/testing php5-cgi/testing php5-cli/testing php5-
common/testing php5-mysql/testing php5-snmp/testing

So if nobody is intervening, I'll reassing the bug to php5 shortly.

With kind regards, Jan.


signature.asc
Description: This is a digitally signed message part.


Bug#537788: [php-maint] Bug#537788: php5 + suhosin with suhosin.session.encrypt = On segfaults

2009-07-24 Thread Jan Wagner
tags 537788 + moreinfo
thanks

Hi,

On Tuesday 21 July 2009, Ondřej Surý wrote:
 php5 sources contains just hardening patch. You refer to optional
 php5-suhosin module, hence I am reassigning bug to correct source
 package.

 Thanks,
 Ondrej.

 2009/7/21 Stefan Bühler light...@stbuehler.de:
  Package: php5
  Version: 5.2.10.dfsg.1-2
 
  + suhosin (0.9.27-1)
 
  Hi!
 
  On debian (sid) with above version of php5 suhosin seems to cause a
  segfault if suhosin.session.encrypt = On is set and an app starts a new
  session. Disabling suhosin completely or setting suhosin.session.encrypt
  = Off it works as expected.
 
  I´m running lighttpd + php5-cgi.

Do you have any steps to reproduce the issue? Possible any scripts or 
anything?

  http://bugs.gentoo.org/show_bug.cgi?id=276583  -- looks very similar, i
  found the solution with suhosin.session.encrypt = Off there.

Looking into the thread, I'm not convinced, that the problem is really the 
suhpsin extension ... especially the most recent comments may indicate that.

With kind regards, Jan.


signature.asc
Description: This is a digitally signed message part.


Bug#537788: [php-maint] Bug#537788: php5 + suhosin with suhosin.session.encrypt = On segfaults

2009-07-21 Thread Ondřej Surý
reassign 537788 php5-suhosin
thank you

Stefan,

php5 sources contains just hardening patch. You refer to optional
php5-suhosin module, hence I am reassigning bug to correct source
package.

Thanks,
Ondrej.

2009/7/21 Stefan Bühler light...@stbuehler.de:
 Package: php5
 Version: 5.2.10.dfsg.1-2

 + suhosin (0.9.27-1)

 Hi!

 On debian (sid) with above version of php5 suhosin seems to cause a
 segfault if suhosin.session.encrypt = On is set and an app starts a new
 session. Disabling suhosin completely or setting suhosin.session.encrypt
 = Off it works as expected.

 I´m running lighttpd + php5-cgi.

 http://bugs.gentoo.org/show_bug.cgi?id=276583  -- looks very similar, i
 found the solution with suhosin.session.encrypt = Off there.



 ___
 pkg-php-maint mailing list
 pkg-php-ma...@lists.alioth.debian.org
 http://lists.alioth.debian.org/mailman/listinfo/pkg-php-maint



-- 
Ondřej Surý ond...@sury.org
http://blog.rfc1925.org/



--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org