Re: [SECURITY] [DSA 2974-1] php5 security update

2014-07-22 Thread Thorsten Alteholz
Hi, On Tue, 22 Jul 2014, Jan Ingvoldstad wrote: Several (if not all) of the issues in DSA 2974-1 are relevant to PHP 5.3.3. Three out of seven CVEs of DSA 2974-1 affect code that is not present in Squeeze. The remaining CVEs are part of the package I asked to test. The other patches don't h

Re: [SECURITY] [DSA 2974-1] php5 security update

2014-07-22 Thread Jan Ingvoldstad
On 18. juli 2014, at 16:28, Marko Randjelovic wrote: > Hi, Hi! > > Some patches from 5.4.4-14+deb7u12 could be unmodified or with > modifications applied to 5.3.3-7+squeeze20. Some of them may be > relevant for security. Since I am not a DD, patches I found could be > useful are attached with

Re: [SECURITY] [DSA 2974-1] php5 security update

2014-07-22 Thread Jan Ingvoldstad
On 22. juli 2014, at 13:45, Jan Ingvoldstad wrote: > It's a bit hard for me to read this, but I assume you're referring to DSA > 2974-1. Astute observation, Watson, you perceive that Marko mentioned this in the subject. D'oh. :) -- Cheers, Jan -- To UNSUBSCRIBE, email to debian-lts-requ.

Re: [SECURITY] [DSA 2974-1] php5 security update

2014-07-18 Thread Marko Randjelovic
Hi, Some patches from 5.4.4-14+deb7u12 could be unmodified or with modifications applied to 5.3.3-7+squeeze20. Some of them may be relevant for security. Since I am not a DD, patches I found could be useful are attached with eventual my modifications. I don't know if they solve the problems nor if