Solved

php upgrade

Posted on 2002-03-07
3
273 Views
Last Modified: 2012-05-04
Hello,

With the recent announcement of the PHP exploit (see http://www.php.net), I have been charged with upgrading all of our servers.  All of them went smoothly - except for one:

Redhat Linux 5.2
Redhat Secureweb 2.0 (Redhat's Apache with SSL, based on Apache 1.3.1)
PHP 3.0.5
(Yes, I know these are all old!)

I have tried the following:
- Dropping in a patched 3.0.18 libphp3.so, compiled on another machine
I gotten several errors, the showstopper being:
undefined symbol: ap_regexec
- compiling 3.0.18 on the Redhat 5.2

- patching and compiling 3.0.5 on the Redhat 5.2
Can't even get it patched, as there are several code changes to the mime.c, I tried dropping in the mime.c from the 3.0.18 and compiling, but no luck.

Is there anyone that has had this situation and was able to upgrade?  Please help!

Thanks,

Tom
0
Comment
Question by:tom419
3 Comments
 
LVL 3

Accepted Solution

by:
rycamor earned 300 total points
ID: 6879164
1. Are you sure your patch was successful? How about documenting exactly what you did to patch the PHP 3.0.18 source, and then your steps to compile.

2. You might not be vulnerable anyway, because the exploit was only documented for PHP versions 3.0.10-3.0.18.

3. BTW, the simple fix, if you don't want to update, is just to disable file uploads in php.ini. If you really need file upload capability, just find a good Perl CGI script for that and call it a day.
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Author Note: Since this E-E article was originally written, years ago, formal testing has come into common use in the world of PHP.  PHPUnit (http://en.wikipedia.org/wiki/PHPUnit) and similar technologies have enjoyed wide adoption, making it possib…
I imagine that there are some, like me, who require a way of getting currency exchange rates for implementation in web project from time to time, so I thought I would share a solution that I have developed for this purpose. It turns out that Yaho…
The viewer will learn how to look for a specific file type in a local or remote server directory using PHP.
The viewer will learn how to create and use a small PHP class to apply a watermark to an image. This video shows the viewer the setup for the PHP watermark as well as important coding language. Continue to Part 2 to learn the core code used in creat…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question