Current time: 11-29-2024, 05:56 PM Hello There, Guest! (LoginRegister)


Post Reply 
[HowTo] PHP5 cgi with bundled gd
Author Message
raphael Offline
Member
***

Posts: 474
Joined: Apr 2007
Reputation: 8
Post: #2
RE: [HowTo] PHP5 cgi with bundled gd
And the benefit is...?
The php package in Debian doesn't use the bundled library because of security reasons.
When a shared library has a security bug and is fixed all the binaries using that library are 'safe'. But if the bundled library code isn't fixed php would still be vulnerable (and let me tell you something, the security team won't fix the bundled one).

This is a fix one, save them all v.s. a fix ALL, waste your time situation; of course Debian uses the former approach (others should do too, why aren't the changes in the bundled libgd2 code included by the main libgd2 library?)
01-05-2008 03:58 AM
Visit this user's website Find all posts by this user Quote this message in a reply
Post Reply 


Messages In This Thread
[HowTo] PHP5 cgi with bundled gd - hbaes - 01-04-2008, 12:03 AM
RE: [HowTo] PHP5 cgi with bundled gd - raphael - 01-05-2008 03:58 AM

Forum Jump:


User(s) browsing this thread: 2 Guest(s)