[Bug 305393] Re: Please upgrade php5 to new upstream version 5.2.7

2008-12-08 Thread Micah Gersten
PHP 5.2.8 Released!
[08-Dec-2008]

The PHP development team would like to announce the immediate
availability of PHP 5.2.8. This release addresses a regression
introduced by 5.2.7 inregard to the magic_quotes functionality, that was
broken by an incorrect fix to the filter extension. All users who have
upgraded to 5.2.7 are encouraged to upgrade to this release,
alternatively you can apply a work-around for the bug by changing
"filter.default_flags=0" in php.ini.


** Summary changed:

- Please upgrade php5 to new upstream version 5.2.7
+ Please upgrade php5 to new upstream version 5.2.8

-- 
Please upgrade php5 to new upstream version 5.2.8
https://bugs.launchpad.net/bugs/305393
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to php5 in ubuntu.

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 305393] Re: Please upgrade php5 to new upstream version 5.2.7

2008-12-08 Thread Chris Coulson
We can just wait until 5.2.8 is released

-- 
Please upgrade php5 to new upstream version 5.2.7
https://bugs.launchpad.net/bugs/305393
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to php5 in ubuntu.

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 305393] Re: Please upgrade php5 to new upstream version 5.2.7

2008-12-08 Thread Micah Gersten
It's been officially removed from php.net, here's the announcement:

PHP 5.2.7 has been removed from distribution
[07-Dec-2008]

Due to a security bug found in the PHP 5.2.7 release, it has been
removed from distribution. The bug affects configurations where
magic_quotes_gpc is enabled, because it remains off even when set to on.
In the meantime, use PHP 5.2.6 until PHP 5.2.8 is later released.


Not sure what to do with this request.

Thanks.

-- 
Please upgrade php5 to new upstream version 5.2.7
https://bugs.launchpad.net/bugs/305393
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to php5 in ubuntu.

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 305393] Re: Please upgrade php5 to new upstream version 5.2.7

2008-12-06 Thread Micah Gersten
Received Blog notification of potential bug:
http://www.macvicar.net/blog/2008/12/critical-bug-in-php-527.html

Here's the text:
Critical Bug in PHP 5.2.7

PHP 5.2.7 was released on Thursday but unfortunately a critical bug was
introduced during the release candidate process that essentially full
disables magic_quotes_gpc even when it’s marked as enabled. The end
result being that if you relied on magic_quotes_gpc being enabled it’s
now not, potentially a security issue.

The other problem is that even if you don’t rely on it being enabled but
have an application which attempts to undo the work of magic_quotes_gpc
you may end up with some data loss. Such code is present within most
applications that want to work with it disabled

This has been fixed in CVS so you can grab a snapshot if you've already
upgraded to PHP 5.2.7, if not then hold out for PHP 5.2.8 which should
appear early next week.

If magic_quotes_gpc doesn’t matter to you and you normally run with it
disabled then this doesn’t really matter.

-- 
Please upgrade php5 to new upstream version 5.2.7
https://bugs.launchpad.net/bugs/305393
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to php5 in ubuntu.

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 305393] Re: Please upgrade php5 to new upstream version 5.2.7

2008-12-05 Thread Chuck Short
Looks reasonable to me according to the changelog.

chuck

-- 
Please upgrade php5 to new upstream version 5.2.7
https://bugs.launchpad.net/bugs/305393
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to php5 in ubuntu.

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs