Re: installing HTTP_Request
| From: | Gregory Beaver | Date: | Thu, 06 Dec 2007 04:58:58 +0000 |
| Subject: | Re: installing HTTP_Request | ||
| References: | 1 2 3 4 5 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-28286@lists.php.net to get a copy of this message | ||
Bennett Haselton wrote:
> At 06:26 PM 12/5/2007 -0600, Gregory Beaver wrote:
>> You are also using a very old version of PHP, one that has many known
>> security vulnerabilities, that may be of greater concern than the
>> upgrading of PEAR, were I in your shoes.
>>
>> As for making it possible to upgrade from 1.3.2, it is possible, but the
>> problem is that 1.3.2 has so many serious bugs in it, it is not capable
>> of doing an upgrade properly, and will leave your system corrupted.
>> This is not something that can be fixed, except by upgrading.
>
> Well all I know is that 4 freshly set up dedicated servers all had PEAR
> 1.3.2 installed on them by default, so I figured that meant it was quite
> common out there. Although I don't know, since it sounds like you don't
> get this question often!
You might want to alert the sysadmins that they are opening their
machine to serious security vulnerabilities with these ancient php/pear
versions, and the fix is ridiculously simple.
> If enough people ask the question maybe there could be an additional
> page on the "Installation" section of the wiki about how to do an
> upgrade from 1.3.2 (which would really be a complete un-install followed
> by an install).
http://pear.php.net/manual/en/faq.php
>> Incidentally, the majority of machines - active machines - on the
>> internet are using PEAR version 1.5.0 or newer, in fact upwards of
>> 99.8%, based on the apache server logs at pear.php.net, so the fact that
>> you are using 1.3.2 puts you in a rather severe minority :).
>
> I suspect your server log stats might be biased by the fact that anybody
> using version 1.3.2 would get an error and stop using the site
> immediately :)
Not true - PEAR 1.3.2 can install packages, it's just not very smart
with php-cgi.
Greg