OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: PHP Vulnerabilities posted on hardened-php.net

From: Alec Berryman (alecthened.net)
Date: Fri Dec 17 2004 - 17:50:03 CST


begin quotation of Sevan / Venture37 on 2004-12-17 22:47:15 +0000:

> Is PHP 4.3.8 Installed from the OpenBSD-stable packages page vulnerable?

Yes.

There was a patch for -current posted early today on ports by the
port maintainer. I'm running 3.6-stable and changed the 'V=' keyword
in the Makefile.inc and recompiled/reinstalled; the process was smooth
and I haven't had any difficulties yet.