Re: Debian PHP upgrade

2015-03-31 Thread Andile Ntebe
Hi Philip Thank you very much for your response. Regards On 2015/03/25, 4:28 PM, "Philip Hands" wrote: >Andile Ntebe writes: > >> Hi >> >> Im not sure why Gareth said PHP, I’m referring to Apache 2.2.22. >> >> The below vulnerabilities seem to affect this version: > >You seem not to have n

Re: Debian PHP upgrade

2015-03-31 Thread Andile Ntebe
Hi Florian Here you go: http://httpd.apache.org/security/vulnerabilities_22.html Regards On 2015/03/28, 10:42 PM, "Florian Weimer" wrote: >* Andile Ntebe: > >> Im not sure why Gareth said PHP, I’m referring to Apache 2.2.22. >> >> The below vulnerabilities seem to affect this version: > >

Re: Debian PHP upgrade

2015-03-31 Thread Florian Weimer
* Andile Ntebe: > On 2015/03/28, 10:42 PM, "Florian Weimer" wrote: > >>* Andile Ntebe: >> >>> Im not sure why Gareth said PHP, I’m referring to Apache 2.2.22. >>> >>> The below vulnerabilities seem to affect this version: >> >>Hi Andile, >> >>Where did you get this list? > Here you go: > > http:

Re: Debian PHP upgrade

2015-03-28 Thread Florian Weimer
* Andile Ntebe: > Im not sure why Gareth said PHP, I’m referring to Apache 2.2.22. > > The below vulnerabilities seem to affect this version: Hi Andile, Where did you get this list? Thanks, Florian -- To UNSUBSCRIBE, email to debian-devel-requ...@lists.debian.org with a subject of "unsubscrib

Re: Debian PHP upgrade

2015-03-25 Thread Philip Hands
Andile Ntebe writes: > Hi > > Im not sure why Gareth said PHP, I’m referring to Apache 2.2.22. > > The below vulnerabilities seem to affect this version: You seem not to have noticed that Debian fixes security issues in stable versions of our packages, so you're comparing the version that Apache

Re: Debian PHP upgrade

2015-03-25 Thread Andile Ntebe
Debian 7.6 All the CVEs for Apache 2.2.22 On 2015/03/25, 1:53 PM, "Paul Wise" wrote: >On Wed, Mar 25, 2015 at 7:22 PM, Andile Ntebe wrote: > >> We have Apache/2.2.22 on our Debian boxes. > >Which Debian version number? > >> Ive tried using apt-get update and apt-get upgrade to try and get us

Re: Debian PHP upgrade

2015-03-25 Thread Paul Wise
On Wed, Mar 25, 2015 at 9:37 PM, Andile Ntebe wrote: > The below vulnerabilities seem to affect this version: BTW: Please install debsecan to determine which packages have unfixed security issues or available security issues: https://wiki.debian.org/DebianSecurity/debsecan Please install debia

Re: Debian PHP upgrade

2015-03-25 Thread Frederic Peters
Hi Andile, > Im not sure why Gareth said PHP, I’m referring to Apache 2.2.22. > > The below vulnerabilities seem to affect this version: > > CVE-2014-0231 > ... As Paul noted earlier, you can use https://security-tracker.debian.org/

Re: Debian PHP upgrade

2015-03-25 Thread Andrew Shadura
Andile, On 25 March 2015 at 14:37, Andile Ntebe wrote: > Hi > > Im not sure why Gareth said PHP, I’m referring to Apache 2.2.22. > > The below vulnerabilities seem to affect this version: If you read the changelog to the latest version available in stable, you'll find answers to all of your ques

Re: Debian PHP upgrade

2015-03-25 Thread Paul Wise
On Wed, Mar 25, 2015 at 9:37 PM, Andile Ntebe wrote: > Im not sure why Gareth said PHP, I’m referring to Apache 2.2.22. > > The below vulnerabilities seem to affect this version: > Is there a way for us to update to the latest version? All of the CVEs you referenced either do not apply to or are

Re: Debian PHP upgrade

2015-03-25 Thread Andile Ntebe
Hi Im not sure why Gareth said PHP, I’m referring to Apache 2.2.22. The below vulnerabilities seem to affect this version: CVE-2014-0231 CVE-2013-5704 CVE-2014-0118

Re: Debian PHP upgrade

2015-03-25 Thread Paul Wise
On Wed, Mar 25, 2015 at 7:22 PM, Andile Ntebe wrote: > We have Apache/2.2.22 on our Debian boxes. Which Debian version number? > Ive tried using apt-get update and apt-get upgrade to try and get us onto the > latest version but with no success. Is there any other way that we could get > Apache

Re: Debian PHP upgrade

2015-03-25 Thread Adam D. Barratt
On 2015-03-25 11:22, Andile Ntebe wrote: We have Apache/2.2.22 on our Debian boxes. Ive tried using apt-get update and apt-get upgrade to try and get us onto the latest version but with no success. Is there any other way that we could get Apache updated? I have to admit I'm confused at this po

Re: Debian PHP upgrade

2015-03-25 Thread Andile Ntebe
Hi Adam How are you? We have Apache/2.2.22 on our Debian boxes. Ive tried using apt-get update and apt-get upgrade to try and get us onto the latest version but with no success. Is there any other way that we could get Apache updated? Please let me know. Regards On 2015/03/25, 10:10 AM, "A

RE: Debian PHP upgrade

2015-03-25 Thread Gareth Webb
Surý; Salvatore Bonaccorso; debian-devel@lists.debian.org; Andile Ntebe Subject: RE: Debian PHP upgrade On 2015-03-25 7:12, Gareth Webb wrote: > Passive-aggressive? > I was merely asking from a security perspective I assume Ondřej was referring to "if we need to move over to a new d

RE: Debian PHP upgrade

2015-03-25 Thread Adam D. Barratt
On 2015-03-25 7:12, Gareth Webb wrote: Passive-aggressive? I was merely asking from a security perspective I assume Ondřej was referring to "if we need to move over to a new distribution that has this updated version of PHP". That's a fairly strong opening gambit for "merely asking", particu

RE: Debian PHP upgrade

2015-03-25 Thread Gareth Webb
; Gareth Webb Cc: debian-devel@lists.debian.org Subject: Re: Debian PHP upgrade On Mon, Mar 23, 2015, at 08:59, Salvatore Bonaccorso wrote: > Hi, > > On Mon, Mar 23, 2015 at 06:58:10AM +, Gareth Webb wrote: > > I would like to know when Debian will be releasing the next vers

Re: Debian PHP upgrade

2015-03-24 Thread Ondřej Surý
On Mon, Mar 23, 2015, at 08:59, Salvatore Bonaccorso wrote: > Hi, > > On Mon, Mar 23, 2015 at 06:58:10AM +, Gareth Webb wrote: > > I would like to know when Debian will be releasing the next version > > of PHP? Currently there is a known security vulnerability in the > > current version of Deb

Re: Debian PHP upgrade

2015-03-23 Thread Salvatore Bonaccorso
Hi, On Mon, Mar 23, 2015 at 06:58:10AM +, Gareth Webb wrote: > I would like to know when Debian will be releasing the next version > of PHP? Currently there is a known security vulnerability in the > current version of Debian, we not sure if we should wait for Debian > to update it or if we ne