PHP version
Moderator: Admins
PHP version
Hello - I am the technical director for govsim.com and I was curious about the PHP version being run on our server (www2.pcdc.net). There has recently been a vulnerability found with PHP 4.3.9 that affects message boards such as vbulletin and phpbb. Would it be possible to upgrade the php version on our server to 4.3.10? Thanks. Mike
-
- Site Admin
- Posts: 710
- Joined: Wed Jun 12, 2002 5:57 pm
- Location: Toronto, Ontario
- Contact:
Re: PHP version
Hi there sullim4,sullim4 wrote:Hello - I am the technical director for govsim.com and I was curious about the PHP version being run on our server (www2.pcdc.net). There has recently been a vulnerability found with PHP 4.3.9 that affects message boards such as vbulletin and phpbb. Would it be possible to upgrade the php version on our server to 4.3.10? Thanks. Mike
This has been looked into for about a week, and we've been deploying other methods of dealing with problems like that (eg. mod_security). I stand by the method of "letting other people, at other companies, make your mistakes for you" and am rarely the first person to rush in on a software upgrade, etc.
There have been several reports of problems with php 4.3.10 that we've been watching on the CPanel forums, though at this time they appear to be in relation to Zend Optimizer (again, why waiting is good, as we have the possible answer before we even have the problem). We will most likely be upgrading the servers within the next couple of days once we've completed our evaluation.
BTW, you're pretty quick, CPanel didn't even pick up the php 4.3.10 patch a week ago (and they have no confirmed security issues, the overflow issues, etc. are a common presence for most scripts).