Re: [PHP] Any idea when 4.3.11 will be released?

2005-01-16 Thread Rasmus Lerdorf
On Sun, 16 Jan 2005, Gal wrote:
> I'm Working in organization which also using php on the Windows platform.
> Because of the security holes in the older version and a COM bug at PHP
> 4.3.10 (http://bugs.php.net/bug.php?id=31159) we are using a problematic
> version.

I'd just roll back to 4.3.9 and do proper input filtering.  As long as you
don't pass raw user data to unserialize or do something like include
"$user_data/foo" while allowing $user_data to be huge, you are fine.

-Rasmus

-- 
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php



Re: [PHP] Any idea when 4.3.11 will be released?

2005-01-16 Thread DvDmanDT
They aren't talking about it on internals.. Not much on QA neither.. So..
Don't expect a release tomorrow.. :p CVS version might be the best option if
that bug is a problem..:p

-- 
// DvDmanDT
MSN: dvdmandt¤hotmail.com
Mail: dvdmandt¤telia.com
"Gal" <[EMAIL PROTECTED]> skrev i meddelandet
news:[EMAIL PROTECTED]
> Hi Jeffery,
>
> Thanks for the info.
>
> I'm happy to read that the problem has been fixed. but i don't intend to
> use a CVS version on a production machine.
>
> This is the reason i asked for info on the official 4.3.11 release date.
> Do you have any idea when it is planned ?
>
> Thanks,
> Gal
>
>
> Jeffery Fernandez wrote:
> > Gal wrote:
> >
> >> Hello,
> >>
> >> I'm Working in organization which also using php on the Windows
platform.
> >> Because of the security holes in the older version and a COM bug at
> >> PHP 4.3.10 (http://bugs.php.net/bug.php?id=31159) we are using a
> >> problematic version.
> >>
> >> Does anyone here knows - what is the status of the release of 4.3.11 ?
> >>
> >> Regards,
> >> Gal
> >>
> > *[23 Dec 2004 2:43am CET] [EMAIL PROTECTED]
> >
> > This bug has been fixed in CVS.
> >
> > Snapshots of the sources are packaged every three hours; this change
> > will be in the next snapshot. You can grab the snapshot at
> > http://snaps.php.net/.
> >
> > cheers,
> > JefferyFernandez
> > http://melbourne.ug.php.net

-- 
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php



Re: [PHP] Any idea when 4.3.11 will be released?

2005-01-16 Thread Gal
Hi Jeffery,
Thanks for the info.
I'm happy to read that the problem has been fixed. but i don't intend to 
use a CVS version on a production machine.

This is the reason i asked for info on the official 4.3.11 release date.
Do you have any idea when it is planned ?
Thanks,
Gal
Jeffery Fernandez wrote:
Gal wrote:
Hello,
I'm Working in organization which also using php on the Windows platform.
Because of the security holes in the older version and a COM bug at 
PHP 4.3.10 (http://bugs.php.net/bug.php?id=31159) we are using a 
problematic version.

Does anyone here knows - what is the status of the release of 4.3.11 ?
Regards,
Gal
*[23 Dec 2004 2:43am CET] [EMAIL PROTECTED]
This bug has been fixed in CVS.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
cheers,
JefferyFernandez
http://melbourne.ug.php.net
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php


Re: [PHP] Any idea when 4.3.11 will be released?

2005-01-16 Thread Jeffery Fernandez
Gal wrote:
Hello,
I'm Working in organization which also using php on the Windows platform.
Because of the security holes in the older version and a COM bug at 
PHP 4.3.10 (http://bugs.php.net/bug.php?id=31159) we are using a 
problematic version.

Does anyone here knows - what is the status of the release of 4.3.11 ?
Regards,
Gal
*[23 Dec 2004 2:43am CET] [EMAIL PROTECTED]
This bug has been fixed in CVS.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
cheers,
JefferyFernandez
http://melbourne.ug.php.net
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php