All my Ubuntu boxes (that I can currently access, that is) have back-port fixes, so all good. Thanks for the heads up Al.

Kind regards

Murray Crane



On 9 May 2012 16:35, Alan Pope <alan@popey.com> wrote:
On 9 May 2012 07:56, Murray Crane <murray.crane@gmail.com> wrote:
> I'm running latest WP on Ubuntu LTS (10.04) using PHP5-CGI and lighttpd. I
> know full well that my PHP5 will be vulnerable (v5.3.2, damn you Ubuntu;
> CATCH UP FOR F**KS SAKE!!!), but I don't know how to go about securing it in
> lighty (if I even need to). I do know that if I point a browser at
> "index.php?-s", I get the front page of my blog back (as if I had left the
> "?-s" off) and not anything that would scream "VULNERABLE!!!" at me.
>

You sure about Ubuntu not putting an update out?

https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.15  suggests otherwise.

Announce went out some days back, and the new packages were already available.

https://lists.ubuntu.com/archives/ubuntu-security-announce/2012-May/001678.html

Al.