Re: [CentOS] PHP updates for CVE-2012-0830 already in the pipeline?

2012-02-03 Thread Leonard den Ottolander
Hello, On Fri, 2012-02-03 at 13:50 +0100, Leonard den Ottolander wrote: > I was wondering if the upstream updates released about 14 > hours ago are already being built. It helps to first check the announce list :) . I hadn't expected such a quick response, I didn't get a warning from my 4am cron

[CentOS] PHP updates for CVE-2012-0830 already in the pipeline?

2012-02-03 Thread Leonard den Ottolander
Hello, The remote code execution issue that got introduced with 5.3.9 has me worried a bit. I was wondering if the upstream updates released about 14 hours ago are already being built. As this appears to be quite a serious issue I'm wondering if it's worth the trouble to downgrade php to a per Jan

Re: [CentOS] PHP updates

2009-11-27 Thread Ian Forde
On Fri, 2009-11-27 at 08:34 -0500, Bob McConnell wrote: > Michael Kress wrote: > > Craig White wrote: > >> and if enough people actually convinced the developers that > >> 5.2.9-2.el5.centos were feasible, then they would probably move it into > >> the 'Extras' repository. > > > > ... here's one t

Re: [CentOS] PHP updates

2009-11-27 Thread John R Pierce
Bob McConnell wrote: > I'll go one further. We run commercial web sites on CentOS 5.3 which > must also be PCI compliant. Because of the security issues, the auditors > have been complaining for two months that we don't have PHP 5.2.11 > installed yet, putting our PCI certification in jeopardy.

Re: [CentOS] PHP updates

2009-11-27 Thread Rob Kampen
Michael Kress wrote: Craig White wrote: and if enough people actually convinced the developers that 5.2.9-2.el5.centos were feasible, then they would probably move it into the 'Extras' repository. ... here's one trying to 'convince'! ;-) I'm using that package from c5-testing since a m

Re: [CentOS] PHP updates

2009-11-27 Thread Karanbir Singh
On 11/27/2009 01:34 PM, Bob McConnell wrote: > We are trying to figure out how to handle this issue short of having to > compile PHP ourselves. That would violate the agreement we have with the > hosting service. The whole PCI DSS issue is fairly important to many people at the moment, and wht do

Re: [CentOS] PHP updates

2009-11-27 Thread Bob McConnell
Michael Kress wrote: > Craig White wrote: >> and if enough people actually convinced the developers that >> 5.2.9-2.el5.centos were feasible, then they would probably move it into >> the 'Extras' repository. > > ... here's one trying to 'convince'! ;-) > I'm using that package from c5-testing sinc

Re: [CentOS] PHP updates

2009-11-27 Thread Michael Kress
Craig White wrote: > and if enough people actually convinced the developers that > 5.2.9-2.el5.centos were feasible, then they would probably move it into > the 'Extras' repository. ... here's one trying to 'convince'! ;-) I'm using that package from c5-testing since a month or so and I encountere

Re: [CentOS] PHP updates

2009-11-25 Thread Craig White
On Wed, 2009-11-25 at 23:22 +0200, Rudi Ahlers wrote: > On Wed, Nov 25, 2009 at 11:13 PM, Craig White wrote: > > For the 2 threads going on about PHP 5.2/5.3... > > > > CentOS tracks upstream whose version is... > > php-5.1.6-23.2.el5_3 > > > > If you want something newer, you have to go off the b

Re: [CentOS] PHP updates

2009-11-25 Thread Rudi Ahlers
On Wed, Nov 25, 2009 at 11:13 PM, Craig White wrote: > For the 2 threads going on about PHP 5.2/5.3... > > CentOS tracks upstream whose version is... > php-5.1.6-23.2.el5_3 > > If you want something newer, you have to go off the beaten path. > > try this...(as root) > wget http://dev.centos.org/ce

[CentOS] PHP updates

2009-11-25 Thread Craig White
For the 2 threads going on about PHP 5.2/5.3... CentOS tracks upstream whose version is... php-5.1.6-23.2.el5_3 If you want something newer, you have to go off the beaten path. try this...(as root) wget http://dev.centos.org/centos/5/CentOS-Testing.repo mv CentOS-Testing.repo /etc/yum.repos.d yu