Status of security support in Debian stable

2018-09-03 Thread jaroslav
Hello, I would like to ask about the status of security support for LAMP packages in Debian stable. I've noticed that security related updates have been lagging behind upstream - for example PHP security updates from Debian usually come out few weeks or even months after upstream release. Whe

Re: PHP5 in Wheezy vulnerable to CVE-2013-2110?

2013-06-20 Thread jaroslav
Dne 20.06.2013 14:13, Thijs Kinkhorst napsal: On Thu, June 20, 2013 09:08, jaros...@thinline.cz wrote: Can someone please confirm that the Wheezy package is really not vulnerable? I tried to use the test code from PHP (attached below) on multiple PHP versions, but it doesn't cause segfaults (as i

PHP5 in Wheezy vulnerable to CVE-2013-2110?

2013-06-20 Thread jaroslav
Hello, I noticed the PHP project released PHP 5.4.16 which among other things fixes CVE-2013-2110 (heap-based buffer overflow in quoted_printable_encode()). According to https://security-tracker.debian.org/tracker/CVE-2013-2110 the Wheezy package (5.4.4-14+deb7u2) is not vulnerable, however w