WireNine Community






Go Back   WireNine Web Hosting Forums > WireNine Forums > Network Status

Network Status Announcements regarding service outages, server reboots, scheduled downtimes, upgrades etc.

Reply
 
Thread Tools Display Modes
  #1  
Old Feb 20th, 2007, 05:49 PM
WN-Ali's Avatar
WN-Ali WN-Ali is offline
WireNine CEO
 
Join Date: Jun 2005
Location: ON, Canada
Posts: 952
Rep Power: 10
WN-Ali is on a distinguished road
Default [Completed] PHP 5.2.1 upgrade on all servers

We have upgraded our PHP 5 installs to the newly released PHP 5.2.0 version on all servers. There are several improvements and new features included in this release, along with an assortment of bug fixes. Here are the details straight from php's web site:

Quote:
Security Enhancements and Fixes in PHP 5.2.1:

* Fixed possible safe_mode & open_basedir bypasses inside the session extension.
* Prevent search engines from indexing the phpinfo() page.
* Fixed a number of input processing bugs inside the filter extension.
* Fixed unserialize() abuse on 64 bit systems with certain input strings.
* Fixed possible overflows and stack corruptions in the session extension.
* Fixed an underflow inside the internal sapi_header_op() function.
* Fixed allocation bugs caused by attempts to allocate negative values in some code paths.
* Fixed possible stack overflows inside zip, imap & sqlite extensions.
* Fixed several possible buffer overflows inside the stream filters.
* Fixed non-validated resource destruction inside the shmop extension.
* Fixed a possible overflow in the str_replace() function.
* Fixed possible clobbering of super-globals in several code paths.
* Fixed a possible information disclosure inside the wddx extension.
* Fixed a possible string format vulnerability in *print() functions on 64 bit systems.
* Fixed a possible buffer overflow inside mail() and ibase_{delete,add,modify}_user() functions.
* Fixed a string format vulnerability inside the odbc_result_all() function.
* Memory limit is now enabled by default.
* Added internal heap protection.
* Extended filter extension support for $_SERVER in CGI and apache2 SAPIs.

The majority of the security vulnerabilities discovered and resolved can in most cases be only abused by local users and cannot be triggered remotely. However, some of the above issues can be triggered remotely in certain situations, or exploited by malicious local users on shared hosting setups utilizing PHP as an Apache module. Therefore, we strongly advise all users of PHP, regardless of the version to upgrade to 5.2.1 release as soon as possible. PHP 4.4.5 with equivalent security corrections is available as well.

The key improvements of PHP 5.2.1 include:

* Several performance improvements in the engine, streams API and some Windows specific optimizations.
* PDO_MySQL now uses buffered queries by default and emulates prepared statements to bypass limitations of MySQL's prepared statement API.
* Many improvements and enhancements to the filter and zip extensions.
* Memory limit is now always enabled, this includes Windows builds, with a default limit of 128 megabytes.
* Added several performance optimizations using faster Win32 APIs (this change means that PHP no longer supports Windows 98).
* FastCGI speed optimized build of PHP for Windows made available for downloading.
* Over 180 bug fixes.
For those making use of PHP 5 functionality, there may have been some minor changes that could potentially break your scripts. It's unlikely, but possible. A complete change log of new features and bug fixes in this release can be found here: http://www.php.net/ChangeLog-5.php#5.2.1

Please let us know if anything breaks at the server level, but the changes should be transparent for the most part.
__________________
Warm Regards,
Ali K, CEO.

WireNine.com | Support Center | Sales | Knowledge base | Flash How-to Tutorials
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Completed] PHP 4.4.6 Upgrade WN-Ali Network Status 0 Mar 20th, 2007 03:09 PM
[Completed] PHP 5.2.0 upgrade on all servers WN-Ali Network Status 0 Dec 4th, 2006 09:22 AM
[Completed] PHP v4.4.4 Upgrade WN-Ali Network Status 1 Aug 22nd, 2006 09:03 AM
[Completed] PHP 4.4.2 Upgrade WN-Ali Network Status 7 Jan 23rd, 2006 06:20 PM
[Completed] Upgrade performed - MySQL 4.1.13 & PHP 4.4.0 WN-Ali Network Status 0 Aug 15th, 2005 05:54 AM


All times are GMT. The time now is 09:39 AM.


Powered by vBulletin
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
  • cPanel Hosting, MySQL Hosting, Litespeed Hosting, R1Soft Backups, Premium Hosting Bandwidth by Internap, SoftLayer Data Center Premium Network