Re: PHP 4.1.2

2004-12-22 Thread Michael Loftis
--On Thursday, December 23, 2004 10:47 +0800 Chad Adlawan <[EMAIL PROTECTED]> wrote: Did you guys perhaps mean the packages from dotdeb.org? Because I just re-checked backports.org, and they still dont package PHP4: http://www.backports.org/debian/dists/stable/ d-oh, yeah. long day :) -- To UN

Re: PHP 4.1.2

2004-12-22 Thread Chad Adlawan
In response to: Michael Loftis <[EMAIL PROTECTED]> wrote: > > FWIW I run the backports.org version of PHP4 pretty much everywhere, > including the hosting company I work for. > And: August MacBeth <[EMAIL PROTECTED]> wrote: > > I've been using backport's 4.3.10 packages in production without

Re: PHP 4.1.2

2004-12-22 Thread Jacob S
On Wed, 22 Dec 2004 23:42:13 +0100 Philipp Kern <[EMAIL PROTECTED]> wrote: > On 22. Dec 2004, at 23:12 Uhr, Jason Lim wrote: > > Little bugfixes and even local exploits... okay... i can understand > > there > > is less urgency. But for REMOTELY exploitable vulnerabilities, i > > think there is a

Re: PHP 4.1.2

2004-12-22 Thread Jason Lim
> > --On Wednesday, December 22, 2004 23:42 +0100 Philipp Kern > <[EMAIL PROTECTED]> wrote: > > > In my opinion it is not worth to backport PHP 4.3 to stable as sarge > > *should* > > be released as soon as security team support is available. > > Sarge is taking an extremely long time to get out th

Re: PHP 4.1.2

2004-12-22 Thread Michael Loftis
--On Wednesday, December 22, 2004 23:42 +0100 Philipp Kern <[EMAIL PROTECTED]> wrote: In my opinion it is not worth to backport PHP 4.3 to stable as sarge *should* be released as soon as security team support is available. Sarge is taking an extremely long time to get out the door. Been nearly

Re: PHP 4.1.2

2004-12-22 Thread Philipp Kern
On 22. Dec 2004, at 23:12 Uhr, Jason Lim wrote: Little bugfixes and even local exploits... okay... i can understand there is less urgency. But for REMOTELY exploitable vulnerabilities, i think there is a much greater urgency and importance. For serious PHP deployment you would consider an actual v

Re: PHP 4.1.2

2004-12-22 Thread Jason Lim
> > I've been using backport's 4.3.10 packages in production without > problems. i had problems with Invision power board but that was fixed by > upgrading to the latest version of Zend. > > I am a little disappointed with debian on this update, i thought we > would have got an update by now Litt

Re: PHP 4.1.2

2004-12-22 Thread Michael Loftis
--On Wednesday, December 22, 2004 22:42 +0800 Jason Lim <[EMAIL PROTECTED]> wrote: Just read all that... not particularly encouraging, as it seems no one is interested in backporting the security fixes or that it is not possible to backport them. I heard there are some kind of mod_rewrite rules

Re: PHP 4.1.2

2004-12-22 Thread August MacBeth
* Jason Lim <[EMAIL PROTECTED]> |__ Wed, Dec 22, 2004 at 10:42:57PM +0800: > > We're all worried. There are 2 threads going on in debian-security > > about this issue: > > > > http://lists.debian.org/debian-security/2004/12/msg00044.html > > http://lists.debian.org/debian-security/2004/12/msg0004

Re: PHP 4.1.2

2004-12-22 Thread Jason Lim
> We're all worried. There are 2 threads going on in debian-security > about this issue: > > http://lists.debian.org/debian-security/2004/12/msg00044.html > http://lists.debian.org/debian-security/2004/12/msg00047.html <...> > > http://lists.debian.org/debian-security/2004/12/msg00054.html > Just r

Re: PHP 4.1.2

2004-12-22 Thread Chad Adlawan
> > Or perhaps you guys think there is no need to worry? > We're all worried. There are 2 threads going on in debian-security about this issue: http://lists.debian.org/debian-security/2004/12/msg00044.html http://lists.debian.org/debian-security/2004/12/msg00047.html > > FWIW dotdeb.org has up

Re: PHP 4.1.2

2004-12-22 Thread aCaB
On 12/22/04 11:03, Jason Lim wrote: Hi all, I was wondering... are you guys concerned about the latest PHP vulnerabilities, which affect the Debian stable 4.1.2? How are you handling it? Debian Security Team still hasn't released any patches, so concerned and worried about this. Or perhaps you guys

PHP 4.1.2

2004-12-22 Thread Jason Lim
Hi all, I was wondering... are you guys concerned about the latest PHP vulnerabilities, which affect the Debian stable 4.1.2? How are you handling it? Debian Security Team still hasn't released any patches, so concerned and worried about this. Or perhaps you guys think there is no need to worry?