Results 1 to 6 of 6

Thread: php 5.2.17 security backports question

  1. #1
    Registered User
    Join Date
    Jun 2012
    Posts
    2
    cPanel/WHM Access Level

    Root Administrator

    Default php 5.2.17 security backports question

    Hello,

    I run the default apache (2.2.22) and php installation (5.2.17) and installed using easyapache through cpanel/WHM.

    Secunia dot com released several security vulnerability notifications today that affect php 5.3x and 5.4x (and presumably 5.2x as well but I could be wrong).

    Some of these vulnerabilities were reported today and others about a month ago. Have they already been backported to php 5.2.17 by the cpanel team when installed using easyapache? If not, will they? Or is the only choice to upgrade to the latest version of php 5.3x or 5.4x to be protected against these latest vulnerabilities?

    We run many websites and unfortunately trying to get the web developers to update their code to work with php 5.3x and newer is a PITA. I'd still like to run php 5.2x but not if it's going to lead to the server getting rooted through arbitrary code execution vulnerabilities in php 5.2x.

    Any info or tips are greatly appreciated.

    Thank you!

    secunia dot com/advisories/49731/ (cve's listed here)
    secunia dot com/advisories/49014/ (cves listed here)

  2. #2
    Member
    Join Date
    Apr 2012
    Posts
    86
    cPanel/WHM Access Level

    Reseller Owner

    Default Re: php 5.2.17 security backports question

    I think you are worried about PHP 5.4 Win32 Code Execution ≈ Packet Storm - this is only a problem on Windows servers, not CentOS/REDHAT as written on https://bugzilla.redhat.com/show_bug.cgi?id=823464

  3. #3
    Member
    Join Date
    Jul 2012
    Posts
    36
    cPanel/WHM Access Level

    Root Administrator

    Default Re: php 5.2.17 security backports question

    I know this might seem like a dumb question, but does cpanel backport fixes from php 5.3 and 5.4 to 5.2? and if so is there a changelog somewhere that lists what cves have been addressed?

    thanks in advance to anyone that knows, my boss is on us to prove we can still use php 5.2 safely

  4. #4
    Member
    Join Date
    Apr 2012
    Posts
    86
    cPanel/WHM Access Level

    Reseller Owner

    Default Re: php 5.2.17 security backports question

    cpanel is leazy for backporing patches into 5.2, while it is safe and this could be done without any problems. we are thinking about compiling 5.2 by ourself to get all patches into 5.2, while we cannot move to 5.3 on many servers with existing customers.

    shame on cpanel development team about this. 5.2. can be safely use with patches from php52-backports - Backported security patches for PHP 5.2.17 from other PHP versions - Google Project Hosting

  5. #5
    cPanel Staff cPanelTristan's Avatar
    Join Date
    Oct 2010
    Location
    somewhere over the rainbow
    Posts
    7,611
    cPanel/WHM Access Level

    Root Administrator

    Default Re: php 5.2.17 security backports question

    The link you provide isn't from the provider of PHP itself but a separate google project to support a deprecated version when the company who provided PHP 5.2 originally isn't even supporting it any longer.

    Please keep in mind that we provide PHP 4 and PHP 5.2 as a courtesy to our customers. If you wish to see us add the patches, then a feature request would be the way to go:

    Feature Requests for cPanel/WHM
    cPResources: Support Options | More Support Options | Forums Search | cPanel.net Site Search | Mailing Lists(Alt) | Docs
    -- Tristan, Technical Analyst III, Forums Specialist, cPanel Tech Support

    Submit a ticket | Check an existing ticket

  6. #6
    Member
    Join Date
    Apr 2012
    Posts
    86
    cPanel/WHM Access Level

    Reseller Owner

    Default Re: php 5.2.17 security backports question

    There is already thread on Feature Requests for cPanel/WHM about security patches to 5.2. But it is not even responded by cPanel dev team.

Similar Threads

  1. php 5.2.17 secuity backports
    By d_t in forum Security
    Replies: 4
    Last Post: 06-05-2012, 02:33 PM
  2. Apache / PHP user security question
    By whl02 in forum cPanel & WHM Discussions
    Replies: 9
    Last Post: 03-29-2010, 02:45 PM
  3. Question about PHP security, setting up multiple php.ini files?
    By sirbrent in forum cPanel & WHM Discussions
    Replies: 0
    Last Post: 10-01-2008, 10:58 AM
  4. PHP suEXEC Support security question
    By equens in forum cPanel & WHM Discussions
    Replies: 5
    Last Post: 06-11-2004, 01:16 PM
  5. question on php security
    By jarek in forum cPanel & WHM Discussions
    Replies: 5
    Last Post: 09-17-2003, 09:57 AM