Now there exist (S)RPMs for PHP on all of RHL73, RHL9 and FC1: https://bugzilla.fedora.us/show_bug.cgi?id=2344
Getting reports on whether these fix the exploits and/or cause any regressions would be appreciated ASAP.
Remember that community projects like fedora legacy are are a two-way street. It's only as good as YOU (yes, I mean *YOU*) make it.
Regards, Peter