Re: installing HTTP_Request

From: Date: Thu, 06 Dec 2007 05:11:12 +0000
Subject: Re: installing HTTP_Request
References: 1 2 3 4 5 6  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-28287@lists.php.net to get a copy of this message
At 10:58 PM 12/5/2007 -0600, Gregory Beaver wrote:
Bennett Haselton wrote: At 06:26 PM 12/5/2007 -0600, Gregory Beaver wrote:
You are also using a very old version of PHP, one that has many known security vulnerabilities, that may be of greater concern than the upgrading of PEAR, were I in your shoes. As for making it possible to upgrade from 1.3.2, it is possible, but
the
problem is that 1.3.2 has so many serious bugs in it, it is not
capable
of doing an upgrade properly, and will leave your system corrupted. This is not something that can be fixed, except by upgrading.
Well all I know is that 4 freshly set up dedicated servers all had PEAR 1.3.2 installed on them by default, so I figured that meant it was quite common out there. Although I don't know, since it sounds like you don't get this question often! You might want to alert the sysadmins that they are opening their machine to serious security vulnerabilities with these ancient php/pear versions, and the fix is ridiculously simple.
I'd say that if 4 out of 4 dedicated hosting providers are doing something wrong, probably most of the rest of them are too, and it's a losing battle to try and set them straight one at a time. The problem seems to be that this "ancient, insecure" version of PEAR is included with CentOS 4.x by default, so I'd try to persuade the CentOS people to fix that. I have no idea if they'd even make changes to 4.x after 5.x is out, I'm sure most people on this list know better than me how that works.
        -Bennett
bennett@peacefire.org     http://www.peacefire.org
(425) 497 9002

« previous php.pear.general (#28287) next »