UPDATE REQUEST: php55u 5.5.13 is available upstream

Bug #1324826 reported by bharper
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
IUS Community Project
Fix Released
Undecided
Unassigned

Bug Description

CVE References

Revision history for this message
Carl George (carl.george) wrote :

Packages have been built and will be placed in the testing repos tonight.

Changed in ius:
status: New → Fix Committed
Revision history for this message
Andy Thompson (2-me) wrote :

PHP 5.5.13 and 5.4.29 introduce a BC issue in unserialize function, which breaks PHPUnit and Doctrine. The next releases will reduce the impact of the BC breakage.

The testing versions of php55u and php54 are affected by this bug, and I'd suggest either:

* waiting for the next PHP release, rather than moving these to stable
* patching the regression as per the head branches PHP-5.5 and PHP-5.4

I've done the latter.

Revision history for this message
Andy Thompson (2-me) wrote :
Revision history for this message
Carl George (carl.george) wrote :

Thank you Andy for the heads up on this. I've created patches against the 5.4.29 and 5.5.13 code base, and added them to our git repos.

https://github.com/iuscommunity-pkg/php55u/commit/93c960bd0049afabc7b955f53dd45983af7d319a
https://github.com/iuscommunity-pkg/php54/commit/fa7b80938667752b7edd852f9b77d7e7ba335be4

New builds are in progress.

Revision history for this message
Carl George (carl.george) wrote :

The new build was successful. The package php55u-5.5.13-3.ius will be in the testing repos tonight.

Revision history for this message
Carl George (carl.george) wrote :

While we normally wait two weeks before moving packages from testing to stable, we will proceed sooner in the case of security vulnerabilities. Since this release contains security fixes (CVE-2014-0238, CVE-2014-0237), we will be pushing it to the stable repos tonight. It may take up to 24 hours to sync with all mirrors.

Changed in ius:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.