Re: AW: Vulnerable PHP version according to nessus

2011-12-28 Thread Florian Weimer
* Jordon Bedwell: > New upstream version is used pretty loosely here. I would hardly > consider a bug fix release a new version. You guys treat versions as > if they're a matter of national security, because 5.3.7 vs 5.3.8 is > obviously gonna have some major major API changes and some way new >

Re: Vulnerable PHP version according to nessus

2011-12-28 Thread Ashley Taylor
Depending on your aim with your www-serv, check out suhosin.org. Some patches that harden PHP when used in multi-user envs. Sent from my iPhone On 28 Dec 2011, at 13:45, Dave Henley wrote: thanks Dave > Date: Wed, 28 Dec 2011 15:31:53 +0200 > From: he...@nerv.fi > To: dhenl...@live.com >

RE: Vulnerable PHP version according to nessus

2011-12-28 Thread Dave Henley
thanks Dave > Date: Wed, 28 Dec 2011 15:31:53 +0200 > From: he...@nerv.fi > To: dhenl...@live.com > CC: j.andra...@gmail.com; j...@debian.org; debian-security@lists.debian.org > Subject: Re: Vulnerable PHP version according to nessus > > On Wed, Dec 28, 2011 at 12:53:13PM +, Dave Henley

Re: Vulnerable PHP version according to nessus

2011-12-28 Thread Henri Salo
On Wed, Dec 28, 2011 at 12:53:13PM +, Dave Henley wrote: > Thnaks, I checked the CVE`s against the changelogs and approx. 50% is covered. > Is there a website of some sort to check what kind of CVE`s have been patched? > If nessus does not provide a reliable report, what is the best next step t

RE: Vulnerable PHP version according to nessus

2011-12-28 Thread Dave Henley
Thnaks, I checked the CVE`s against the changelogs and approx. 50% is covered. Is there a website of some sort to check what kind of CVE`s have been patched? If nessus does not provide a reliable report, what is the best next step to take here? Are there any howto`s or tutorials on howto secure a

Re: AW: Vulnerable PHP version according to nessus

2011-12-28 Thread Jordon Bedwell
On Wed, Dec 28, 2011 at 2:54 AM, Adam D. Barratt wrote: > On 28.12.2011 07:56, Patrick Geschke wrote: >> >> Hey, >> >> @Maintainers: Whats the overall Status of the package? >> >> According to php.net 5.3.8 is stable. > > > 5.3.8 is in both testing and unstable - see > http://packages.qa.debian.or

Re: Vulnerable PHP version according to nessus

2011-12-28 Thread Jonas Andradas
2011/12/28 Moritz Mühlenhoff > Dave Henley schrieb: > > --_08b89ad2-8af0-454c-bd3d-7274adf10707_ > > Content-Type: text/plain; charset="iso-8859-1" > > Content-Transfer-Encoding: quoted-printable > > > > > > I recently installed a Debian Squeeze system along with apache2 and PHP5. > > The system

Re: Vulnerable PHP version according to nessus

2011-12-28 Thread Moritz Mühlenhoff
Dave Henley schrieb: > --_08b89ad2-8af0-454c-bd3d-7274adf10707_ > Content-Type: text/plain; charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > > I recently installed a Debian Squeeze system along with apache2 and PHP5. > The system is fully up-to-date and the following php pack

Re: AW: Vulnerable PHP version according to nessus

2011-12-28 Thread Adam D. Barratt
On 28.12.2011 07:56, Patrick Geschke wrote: Hey, @Maintainers: Whats the overall Status of the package? According to php.net 5.3.8 is stable. 5.3.8 is in both testing and unstable - see http://packages.qa.debian.org/p/php5.html Debian stable doesn't generally get new upstream versions of p

Re: Vulnerable PHP version according to nessus

2011-12-28 Thread Henrik Ahlgren
On Wed, Dec 28, 2011 at 07:59:08AM +, Dave Henley wrote: > When I scan my system for vulnerabillities with nessus I get the follwoing > high risk output: > > Synopsis: The remote web server uses a version of PHP that is affected by > multiple vulnerabilities. > > Description > According to i

AW: Vulnerable PHP version according to nessus

2011-12-28 Thread Patrick Geschke
Hey, @Maintainers: Whats the overall Status of the package? According to php.net 5.3.8 is stable. Greetings, Patrick -- Patrick Geschke Systemadministration Top Arbeitgeber 2011! KiKxxl wurde von TOP JOB als zweitbester Arbeitgeber in Deutschland ausgezeichnet. KiKxxl GmbH Mindener Strasse