Slackware: 2006-217-01: php Security Update
Summary
Here are the details from the Slackware 10.2 ChangeLog: patches/packages/php-4.4.3-i486-1_slack10.2.tgz: Upgraded to php-4.4.3. From the announcement of the release: The security issues resolved include the following: * Disallow certain characters in session names. * Fixed a buffer overflow inside the wordwrap() function. * Prevent jumps to parent directory via the 2nd parameter of the tempnam() function. * Improved safe_mode check for the error_log() function. * Fixed cross-site scripting inside the phpinfo() function. The PHP 4.4.3 release announcement may be found on their web site: https://www.php.net/ (* Security fix *)
Where Find New Packages
Updated package for Slackware 10.2:
Updated package for Slackware -current:
MD5 Signatures
Slackware 10.2 package:
417d976f97a53240868e5c715f1ba00b php-4.4.3-i486-1_slack10.2.tgz
Slackware -current package:
713b87c55978e85275c27e720c595ef4 php-4.4.3-i486-1.tgz
Installation Instructions
Installation instructions: Upgrade the package as root: # upgradepkg php-4.4.3-i486-1_slack10.2.tgz