简体   繁体   English

您可以在PHP 5.3.8上使用PHP 5.3.7 suhosin-patch吗?

[英]Can you use a PHP 5.3.7 suhosin-patch on PHP 5.3.8?

I am building a custom PHP rpm for PHP 5.3.8. 我正在为PHP 5.3.8构建自定义PHP rpm。 Unfortunately, suhosin's download site does not have a 0.9.10 5.3.8 patch while they do for 5.3.7 (http://www.hardened-php.net/suhosin/download.html). 不幸的是,suhosin的下载站点没有针对5.3.7的0.9.10 5.3.8补丁(http://www.hardened-php.net/suhosin/download.html)。

Looking at PHP.net's changelog for 5.3.7, extremely little changed in 5.3.8, mostly fixes for some issue in 5.3.7. 查看PHP.net的5.3.7更改日志,在5.3.8中变化很小,主要是在5.3.7中修复了某些问题。 Does anyone know if it would be safe to deploy a 5.3.7 suhosin patch to 5.3.8 seeing the two PHP builds are so similar? 有谁知道将5.3.7 suhosin补丁部署到5.3.8是否安全,因为看到两个PHP版本是如此相似?

I see some distros like CentOS have a PHP 5.3.8 package with suhosin patch 0.9.10, so I am assuming they've managed to make it work somehow. 我看到一些发行版(例如CentOS)具有suhosin补丁0.9.10的PHP 5.3.8软件包,因此我假设他们已经设法使其工作。

Cheers, 干杯,

Tim 提姆

Yes, it should be safe. 是的,应该很安全。 5.3.8 fixed only two issues in 5.3.7 (a crypt and a mysqlnd+ssl problem). 5.3.8仅修复了5.3.7中的两个问题(一个crypt和一个mysqlnd + ssl问题)。

But you should reconsider applying the Suhosin patch. 但是您应该重新考虑应用Suhosin补丁。 Nowadays there is little necessity for it, as the important changes are already in PHP itself. 如今,几乎没有必要这样做了,因为重要的更改已经在PHP本身中了。

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM