summaryrefslogtreecommitdiff
path: root/www/ap-php4/MESSAGE
AgeCommit message (Collapse)AuthorFilesLines
2003-12-17update MESSAGE with instructions for Apache 2.x, which needs AddHandlerjdolecek1-2/+11
rather than AddType problem reported in pkg/23536 by Makoto Fujiwara
2002-08-26format and word Apache module MESSAGEs consistently.grant1-8/+6
2002-02-28Update php4 and ap-php4 to 4.1.2. Changes from version 4.1.1 include:jlam1-2/+2
- Fixed start up failure when mm save handler is used and there is multiple SAPIs are working at the same time. (Yasuo) - Fixed a buffer overflow in the RFC-1867 file upload code (Stefan) <===> SECURITY NOTE <===> Note that the buffer overflow fix is a major security fix. Quoting from the security advisory at: http://security.e-matters.de/advisories/012002.html "PHP supports multipart/form-data POST requests (as described in RFC1867) known as POST fileuploads. Unfourtunately there are several flaws in the php_mime_split function that could be used by an attacker to execute arbitrary code. During our research we found out that not only PHP4 but also older versions from the PHP3 tree are vulnerable. [...] "If you are running PHP 4.0.3 or above one way to workaround these bugs is to disable the fileupload support within your php.ini (file_uploads = Off). If you are running php as module keep in mind to restart the webserver. Anyway you should better install the fixed or a properly patched version to be safe."
2001-11-01Move pkg/ files into package's toplevel directoryzuntum1-0/+16