Re: Question about PHP safe mode

2015-06-24 Thread Markus Rosjat
Hey Guys, thanks for the response Am 23.06.2015 um 11:56 schrieb Heiko Zimmermann: Markus, are you kidding? http://www.cvedetails.com/vulnerability-list/vendor_id-74/product_id-128/version_id-50739/PHP-PHP-5.2.5.html Im aware that php isn't a thing you want to use in a 5.2.4 but we don't

Re: Question about PHP safe mode

2015-06-24 Thread Stuart Henderson
On 2015-06-24, Markus Rosjat ros...@ghweb.de wrote: And OpenBSD 4.2 is released Nov 1, 2007. You dont think it is important to upgrade? Sure it is, if you grand me 35h/day I will upgrade it right now ... If you don't have time to upgrade, you surely don't have time to investigate a security

Re: Question about PHP safe mode

2015-06-23 Thread Stuart Henderson
On 2015-06-23, Markus Rosjat ros...@ghweb.de wrote: Hi there, just a short question... I have quiet old 4.2 OpenBSD with a 5.2.4 PHP version. The safe_mode is on, a Costumer wants to have it off. Is there any security risk to it or do I need to check something on the system level to

Question about PHP safe mode

2015-06-23 Thread Markus Rosjat
Hi there, just a short question... I have quiet old 4.2 OpenBSD with a 5.2.4 PHP version. The safe_mode is on, a Costumer wants to have it off. Is there any security risk to it or do I need to check something on the system level to disable it but still have my environement secured ?

Re: Question about PHP safe mode

2015-06-23 Thread Heiko Zimmermann
Markus, are you kidding? http://www.cvedetails.com/vulnerability-list/vendor_id-74/product_id-128/version_id-50739/PHP-PHP-5.2.5.html And OpenBSD 4.2 is released Nov 1, 2007. You dont think it is important to upgrade? Best Regards, Heiko Am 23.06.2015 um 11:44 schrieb Markus Rosjat: Hi