{"id":25,"date":"2008-02-04T16:43:50","date_gmt":"2008-02-04T09:43:50","guid":{"rendered":"http:\/\/blog.whplus.com\/2008\/02\/04\/upgrade-apache-php.html"},"modified":"2008-02-04T16:43:50","modified_gmt":"2008-02-04T09:43:50","slug":"upgrade-apache-php","status":"publish","type":"post","link":"https:\/\/www.whplus.com\/blog\/2008\/02\/04\/upgrade-apache-php.html","title":{"rendered":"Upgrade Apache &#038; PHP"},"content":{"rendered":"<p>Saat ini kami telah mengupgrade Apache dan PHP di server machine04.<br \/>\nChanges with Apache 1.3.41<\/p>\n<p>*) SECURITY: CVE-2007-6388 (cve.mitre.org)<br \/>\nmod_status: Ensure refresh parameter is numeric to prevent<br \/>\na possible XSS attack caused by redirecting to other URLs.<br \/>\nReported by SecurityReason.  [Mark Cox]<\/p>\n<p>Changes with Apache 1.3.40 (not released)<\/p>\n<p>*) SECURITY: CVE-2007-5000 (cve.mitre.org)<br \/>\nmod_imap: Fix cross-site scripting issue.  Reported by JPCERT.<br \/>\n[Joe Orton]<\/p>\n<p>*) SECURITY: CVE-2007-3847 (cve.mitre.org)<br \/>\nmod_proxy: Prevent reading past the end of a buffer when parsing<br \/>\ndate-related headers.  PR 41144.<br \/>\nWith Apache 1.3, the denial of service vulnerability applies only<br \/>\nto the Windows and NetWare platforms.<br \/>\n[Jeff Trawick]<\/p>\n<p>*) More efficient implementation of the CVE-2007-3304 PID table<br \/>\npatch. This fixes issues with excessive memory usage by the<br \/>\nparent process if long-running and with a high number of child<br \/>\nprocess forks during that timeframe. Also fixes bogus &#8220;Bad pid&#8221;<br \/>\nerrors. [Jim Jagielski, Jeff Trawick]<\/p>\n<p><strong>Security Enhancements and Fixes in PHP 4.4.8:<\/strong><\/p>\n<ul>\n<li>Improved fix for MOPB-02-2007.<\/li>\n<li>Fixed an integer overflow inside chunk_split(). Identified by Gerhard Wagner.<\/li>\n<li>Fixed integer overlow in str[c]spn().<\/li>\n<li>Fixed regression in glob when open_basedir is on introduced by #41655 fix.<\/li>\n<li>Fixed money_format() not to accept multiple %i or %n tokens.<\/li>\n<li>Addded &#8220;max_input_nesting_level&#8221; php.ini option to limit nesting level of input variables. Fix for MOPB-03-2007.<\/li>\n<li>Fixed INFILE LOCAL option handling with MySQL &#8211; now not allowed when open_basedir or safe_mode is active.<\/li>\n<li>Fixed session.save_path and error_log values to be checked against open_basedir and safe_mode (CVE-2007-3378).<\/li>\n<\/ul>\n<p>For a full list of changes in PHP 4.4.8, see the <a href=\"http:\/\/www.php.net\/ChangeLog-4.php#4.4.8\">ChangeLog<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Saat ini kami telah mengupgrade Apache dan PHP di server machine04. Changes with Apache 1.3.41 *) SECURITY: CVE-2007-6388 (cve.mitre.org) mod_status: Ensure refresh parameter is numeric to prevent a possible XSS attack caused by redirecting to other URLs. Reported by SecurityReason. [Mark Cox] Changes with Apache 1.3.40 (not released) *) SECURITY: CVE-2007-5000 (cve.mitre.org) mod_imap: Fix cross-site\u2026 <span class=\"read-more\"><a href=\"https:\/\/www.whplus.com\/blog\/2008\/02\/04\/upgrade-apache-php.html\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-25","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.whplus.com\/blog\/wp-json\/wp\/v2\/posts\/25","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whplus.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whplus.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whplus.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whplus.com\/blog\/wp-json\/wp\/v2\/comments?post=25"}],"version-history":[{"count":0,"href":"https:\/\/www.whplus.com\/blog\/wp-json\/wp\/v2\/posts\/25\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.whplus.com\/blog\/wp-json\/wp\/v2\/media?parent=25"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whplus.com\/blog\/wp-json\/wp\/v2\/categories?post=25"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whplus.com\/blog\/wp-json\/wp\/v2\/tags?post=25"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}