All my Ubuntu boxes (that I can currently access, that is) have back-port fixes, so all good. Thanks for the heads up Al.
On 9 May 2012 07:56, Murray Crane <murray.crane@gmail.com> wrote:You sure about Ubuntu not putting an update out?
> I'm running latest WP on Ubuntu LTS (10.04) using PHP5-CGI and lighttpd. I
> know full well that my PHP5 will be vulnerable (v5.3.2, damn you Ubuntu;
> CATCH UP FOR F**KS SAKE!!!), but I don't know how to go about securing it in
> lighty (if I even need to). I do know that if I point a browser at
> "index.php?-s", I get the front page of my blog back (as if I had left the
> "?-s" off) and not anything that would scream "VULNERABLE!!!" at me.
>
https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.15 suggests otherwise.
Announce went out some days back, and the new packages were already available.
https://lists.ubuntu.com/archives/ubuntu-security-announce/2012-May/001678.html
Al.