Results 1 to 8 of 8
  1. #1
    Join Date
    Apr 2006
    Posts
    413
    Plugin Contributions
    0

    Default PHP versions prior to 5.3.12 and 5.4.2 are vulnerable.

    1. PHP CGI Bug - http://arstechnica.com/security/2014...-22-months-on/ --- PHP versions prior to 5.3.12 and 5.4.2 are vulnerable.

    As I still have a zencart site left I need to ask for clarification on this post by DrByte today. I understand that 1.51 does not work under php 5.4 without code modification. I do not see exactly what modifications are required.

    secondly, does the Dr mean (versions prior to 5.3.12 and 5.4.2 are vulnerable) therefore any version prior to 5.4.2 is vulnerable?.

  2. #2
    Join Date
    Jan 2004
    Posts
    66,378
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: PHP versions prior to 5.3.12 and 5.4.2 are vulnerable.

    Quote Originally Posted by jetx View Post
    does the Dr mean (versions prior to 5.3.12 and 5.4.2 are vulnerable) therefore any version prior to 5.4.2 is vulnerable?.
    My understanding of the statement (it wasn't mine, I was only quoting it) is that PHP 5.3.1 thru 5.3.11 are vulnerable, and 5.4.0 and 5.4.1 are vulnerable. The quoted article makes no mention of PHP 5.2.xxx versions specifically, but I haven't pursued that further; you may wish to.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Jan 2007
    Location
    Australia
    Posts
    6,167
    Plugin Contributions
    7

    Default Re: PHP versions prior to 5.3.12 and 5.4.2 are vulnerable.

    PHP V5.2.X is reaching end of life. There are multiple vulnerabilities. The URL below lists them. This URL is specifically for v5.2.17 which is/was the default version used by a number of distribution of the time and is still in widespread use :-(
    http://www.cvedetails.com/vulnerabil...HP-5.2.17.html

  4. #4
    Join Date
    Apr 2006
    Posts
    413
    Plugin Contributions
    0

    Default Re: PHP versions prior to 5.3.12 and 5.4.2 are vulnerable.

    My issue is whether upgrading php to 5.5. will break zencart. Does anyone know what, if any, files are going to require code edits. Thanks.

    note: besides timezone.
    Last edited by jetx; 10 Apr 2014 at 02:18 AM.

  5. #5
    Join Date
    Apr 2006
    Posts
    413
    Plugin Contributions
    0

    Default Re: PHP versions prior to 5.3.12 and 5.4.2 are vulnerable.

    From this: http://www.zen-cart.com/entry.php?6-...nd-5-5-and-5-6

    I would suspect that many mods will not function correctly under php 5.5.

    List of current mods (if anybody knows, please comment). I really don't want to upgrade and find the site is broken.

    discount mod, table discounts (swguy)
    COWOA
    Ceon Manual Card
    Cross Sell Advanced (prowebs)
    Direct Bank Deposit
    Testimonial Manager
    Last edited by jetx; 10 Apr 2014 at 02:32 AM. Reason: oh.. and Ceon Advanced Shipper

  6. #6
    Join Date
    Apr 2006
    Posts
    413
    Plugin Contributions
    0

    Default Re: PHP versions prior to 5.3.12 and 5.4.2 are vulnerable.

    http://www.zen-cart.com/showthread.p...g-offset/page4

    = a big can of worms.. No dev confirmed fix for 1.51, just a lot of attempts. So in order to run the site error free it is necessary to retain a vulnerable version of php. Is this basically correct?

  7. #7
    Join Date
    Apr 2006
    Posts
    413
    Plugin Contributions
    0

    Default Re: PHP versions prior to 5.3.12 and 5.4.2 are vulnerable.

    So, to run securely I would need to recompile php as an apache module rather than cgi? Just confirming, thanks.

  8. #8
    Join Date
    Apr 2006
    Posts
    413
    Plugin Contributions
    0

    Default Re: PHP versions prior to 5.3.12 and 5.4.2 are vulnerable.

    Upgraded php to 5.3.28, deprecated but I suppose better than what I had (5.2.1.7). Thanks for the link DrB.

 

 

Similar Threads

  1. Upcoming versions - 1.5.3 and 1.6.0 -- compatible with PHP 5.4, 5.5, 5.6
    By DrByte in forum Zen Cart Release Announcements
    Replies: 0
    Last Post: 24 May 2014, 02:32 AM
  2. Can Templates from Prior Versions Be Added to Later Versions?
    By PSurf in forum Templates, Stylesheets, Page Layout
    Replies: 18
    Last Post: 6 Dec 2011, 02:38 AM
  3. Replies: 4
    Last Post: 6 May 2011, 11:24 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR