I attempted to upgrade PHP via CPanel from 5.2.9 to 5.3.10.
Due to the exploit found here. Hash collision DoS vulnerability fixed in PHP 5.3.9 - security, Exploits / vulnerabilities - CIO
I was wondering with Redhat/Centos system a yum update would grab the next release that was not vulnerable, as the patch was sent out about February 3/4. Is there any type of option such as that for CPanel, or do I need to go to version 5.3.10? Additionally, after I attempted to upgrade, PHP segfaulted. The system that I was working on is a 24 hour use system for radio stations, so there's no good time to really allot for downtime, there are better hours than some, but... I would like to know if there is anything that may provide assistance.
I upgraded CPanel, then upgraded PHP as recommended. However, after the issue, I was unable to choose a PHP handler, and every PHP file I tried to visit was downloading on my machine.
I received the following.
------
php -v
Warning: Module 'ionCube Loader' already loaded in Unknown on line 0
The ionCube PHP Loader is disabled because of startup problems.
Segmentation fault
------
To fix this I forced updated CPanel. I however, did this after downgrading back to PHP 5.2.9.



LinkBack URL
About LinkBacks
Reply With Quote




