[Mediawiki-l] MediaWiki and PHP 5.3.5/5.2.17

David Benfell benfell at parts-unknown.org
Thu Jan 13 06:04:10 UTC 2011


On Thu, 13 Jan 2011, Tim Starling wrote:

> If you're running MediaWiki on a 32-bit platform, you should upgrade
> to PHP 5.3.5, PHP 5.2.17 or a patched version of PHP from a Linux
> distribution which includes a fix for CVE-2010-4645. If you run
> MediaWiki on a 32-bit platform with an earlier version of PHP, you
> will be vulnerable to a denial-of-service vulnerability.

Debian users might want to consider the dotdeb versions:

http://www.dotdeb.org/instructions/

On Lenny, this will upgrade you from PHP 5.2 to PHP 5.3 which may be
a compatibility issue for other software.  (And I'm guessing the
list admins would rather we not discuss PHP upgrade headaches here).

-- 
David Benfell <benfell at parts-unknown.org>
http://www.parts-unknown.org/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 198 bytes
Desc: Digital signature
Url : http://lists.wikimedia.org/pipermail/mediawiki-l/attachments/20110112/5df62a41/attachment.pgp 


More information about the MediaWiki-l mailing list