Bug#336645: Bug 336645: PHP 4.4.1 Security Fixes

2006-02-02 Thread Nick Jenkins
Hi, I'm sorry, but I have a question: Is Sarge / stable going to get an update for these problems? In particular, CVE-2005-3390 (GLOBALS array overwrite) for PHP, which I believe Sarge / stable is vulnerable to (CVE entry says it applies to "PHP 4.x up to 4.4.0"), and it is (IMO) a real-world se

Bug#336645: Bug 336645: PHP 4.4.1 Security Fixes

2006-01-11 Thread Nick Jenkins
According to http://lwn.net/Articles/159103/ , it's looking like Debian is the last major distro without a fix for this. Could perhaps the recent Ubuntu updates ( http://lwn.net/Alerts/165505/ ), which were for PHP 4.3.8, be of use to Sarge? All the best, Nick.