Re: PHP Vulnerability

2002-07-24 Thread Emmanuel Seyman
On Wed, Jul 24, 2002 at 09:03:07PM +0200, Ismael Touama wrote: > > How can you ensure of that ? > I should have the same behave than João. > RH73 was out before the found of this vulnerabilty isn't it ? The advisory says only versions 4.2.0 and 4.2.1 of php are vulnerable. [manu@orient manu]$ rp

Re: PHP Vulnerability

2002-07-24 Thread Javier Gostling
On 2002.07.24 12:06 João Borsoi Soares wrote: > My RH7.3 has PHP version 4.1.2-7. In the php.net it > tells that PHP versions 4.2.0 and 4.2.1 have the > vunarability. Are you shure we have to do the patch? No. The CERT advisory states that versions prior to 4.2.0 are not vulnerable. I think this

Re: PHP Vulnerability

2002-07-24 Thread Eric Wood
The 4.1.2-7 (which came with 7.3) shouldn't have the vulnerability. If it did RH would have whipped out a new php package for the 7.x distro. -eric wood - Original Message - From: "João Borsoi Soares" <[EMAIL PROTECTED]> > My RH7.3 has PHP version 4.1.2-7. In the php.net it > tells that

RE: PHP Vulnerability

2002-07-24 Thread Ismael Touama
Hi Emmanuel, > > My RH7.3 has PHP version 4.1.2-7. In the php.net it > > tells that PHP versions 4.2.0 and 4.2.1 have the > > vunarability. Are you shure we have to do the patch? > You don't. > No Red Hat distrib is vulnerable to the latest PHP bug. > Emmanuel How can you ensure of that ? I sho

Re: PHP Vulnerability

2002-07-24 Thread Emmanuel Seyman
On Wed, Jul 24, 2002 at 01:06:34PM -0300, João Borsoi Soares wrote: > > My RH7.3 has PHP version 4.1.2-7. In the php.net it > tells that PHP versions 4.2.0 and 4.2.1 have the > vunarability. Are you shure we have to do the patch? You don't. No Red Hat distrib is vulnerable to the latest PHP bug.

RE: PHP Vulnerability

2002-07-24 Thread João Borsoi Soares
/www.php.net > > Anthony > > > -Original Message- > > From: [EMAIL PROTECTED] > > [mailto:[EMAIL PROTECTED]]On Behalf Of > Frederic Herman > > Sent: Wednesday, July 24, 2002 9:35 AM > > To: [EMAIL PROTECTED] > > Subject: PHP Vulnerability > &g

RE: PHP Vulnerability

2002-07-24 Thread Anthony Abby
Yes it does and yes there is a patch available. http://www.php.net Anthony > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]]On Behalf Of Frederic Herman > Sent: Wednesday, July 24, 2002 9:35 AM > To: [EMAIL PROTECTED] > Subject:

PHP Vulnerability

2002-07-24 Thread Frederic Herman
Does the RH 7.3 distro rpm for PHP have the new PHP vulnerability? If so, is there a patch yet? Fred ___ Redhat-list mailing list [EMAIL PROTECTED] https://listman.redhat.com/mailman/listinfo/redhat-list

About last announced PHP vulnerability...

2002-03-22 Thread Ismael Touama
Hi there, on the errata page it is downloadable only for i386 architecture. Is that mean that I do not need these rpms if I'm on i686 ? On my system a rpm -qa |grep 'php' gives details above... asp2php-0.75.17-1 php-4.0.6-7 asp2php-gtk-0.75.17-1 php-imap-4.0.6-7 php-pgsqlp-4.0.6-7 php-ldap-4.0.6-