Community Forums
Connect with us on LinkedIn
  
+ Reply to Thread
Results 1 to 14 of 14
  1. #1
    Member
    Join Date
    Feb 2007
    Posts
    286

    Default Php 5.2.7

    Hi,

    When can we expect it on easyapache?

  2. #2
    Member
    Join Date
    Mar 2007
    Posts
    133

  3. #3
    Member rhenderson's Avatar
    Join Date
    Apr 2005
    Location
    Oklahoma
    Posts
    742

    Default

    Quote Originally Posted by Lazek View Post
    I voted for it
    Regards,
    Randy
    Affordable Web Hosting
    _________________________

  4. #4
    Registered User
    Join Date
    Sep 2007
    Posts
    4

    Default

    There are a number of very important security fixes in PHP 5.2.7, so hopefully we'll see it soon.

  5. #5
    Member
    Join Date
    Feb 2007
    Posts
    286

    Default

    Quote Originally Posted by TopOTheMorning View Post
    There are a number of very important security fixes in PHP 5.2.7, so hopefully we'll see it soon.
    If I'm right, it will be ready tomorrow or one day after.

  6. #6
    Member
    Join Date
    Feb 2008
    Location
    Sweden
    Posts
    18

    Default

    I think it just was set to "in progress" status

  7. #7
    Member
    Join Date
    Oct 2004
    Posts
    45

    Default

    With the following on the 5.2.7 release page at php.net...

    Code:
    Due to unfortunate regressions installing 5.2.7 is highly discouraged
    ... I am a little confused as to the rush.

    Yes, it might introduce several security fixes, but it also introduces a known regression problem that needs a specific entry into the php.ini file.

    Now, for those who run suphp / suEXEC and happen to have php.ini files in user directories for any reason then "rushing" into this release and finding all the php.ini files on a system and adding the recommended config to the file is a fair bit f work - especially when it comes to the next upgrade and then going and subsequently stripping out the php.ini "fix" for this known problem.

    Do it once, do it right or do it wrong and do it often.....

  8. #8
    Member
    Join Date
    Feb 2008
    Location
    Sweden
    Posts
    18

    Default

    The bug in 5.2.7 can be worked around with a setting in php.ini apparently.

    Beside: There is absolutely nothing wrong with having security fixes pushed out as fast as possible, even if it in this case was a new bug presented with the release.

    Sometimes it can be wise to wait with updates if they are not security related. The latest MySQL release is such a case.

  9. #9
    Registered User
    Join Date
    Sep 2007
    Posts
    4

    Default

    It looks like PHP 5.2.7, while patching a number of critical security holes, is itself broken in a potentially big way.

    http://www.suspekt.org/2008/12/07/ph...es_gpc-broken/

    According to that source:
    The fix for this was already commited to the PHP CVS and PHP 5.2.8 will be released next week.
    So it looks like we won't have long to wait for PHP 5.2.8, at least.

  10. #10
    Member
    Join Date
    Feb 2007
    Posts
    286

    Default

    Irony. They've released like 6 or 5 release candidates and delayed it to make sure there are no bugs left...

  11. #11
    Member whplus's Avatar
    Join Date
    Dec 2007
    Location
    Behind your business
    Posts
    59

    Default

    From http://php.net
    PHP 5.2.7 has been removed from distribution

    [07-Dec-2008] Due to a security bug found in the PHP 5.2.7 release, it has been removed from distribution. The bug affects configurations where magic_quotes_gpc is enabled, because it remains off even when set to on. In the meantime, use PHP 5.2.6 until PHP 5.2.8 is later released.
    Susan,
    Whplus - Web Hosting Murah
    http://www.whplus.com

  12. #12
    Member
    Join Date
    Mar 2007
    Posts
    133

    Default PHP 5.2.8 Released

    PHP 5.2.8 Released!
    [08-Dec-2008]
    The PHP development team would like to announce the immediate availability of PHP 5.2.8. This release addresses a regression introduced by 5.2.7 inregard to the magic_quotes functionality, that was broken by an incorrect fix to the filter extension. All users who have upgraded to 5.2.7 are encouraged to upgrade to this release, alternatively you can apply a work-around for the bug by changing "filter.default_flags=0" in php.ini.


    Bug: 8277
    http://bugzilla.cpanel.net/show_bug.cgi?id=8277
    Last edited by Ivan A; 12-08-2008 at 04:43 PM.

  13. #13
    Member
    Join Date
    Dec 2003
    Location
    PA
    Posts
    110
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Security Metrics is already screaming about php 5.2.8

    Solution: Upgrade to PHP version 5.2.8 or later. Note that 5.2.7 was been removed from distribution because of a regression in that version that results in the 'magic_quotes_gpc' setting remaining off even if it was set to on.

  14. #14
    Member
    Join Date
    Feb 2007
    Posts
    286

    Default

    Quote Originally Posted by merlinpa1969 View Post
    Security Metrics is already screaming about php 5.2.8
    By that you mean screaming how bad it is or how urgent you require to run php upgrade?

    EasyApache now has 5.2.8 by the way

Similar Threads & Tags
Similar threads

  1. Individual php.ini files for PHP FCGI and PHP CGI
    By Miraenda in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 08-22-2011, 08:55 AM
  2. Two php extentions (index.php.php)
    By mcyates in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 04-02-2007, 09:30 PM
  3. Replies: 5
    Last Post: 01-05-2007, 12:41 PM
  4. New VPS site loading but clicking php link just redirect to index.php
    By ozegreatdeals in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 01-20-2006, 06:38 AM
  5. php safe_mode on and /usr/lib/php/DB.php error
    By naox in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 10-09-2005, 05:49 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube