To: General Red Hat Linux discussion list <redhat-list redhat com>
Subject: Re: php pack() security update
Date: Mon, 20 Dec 2004 14:51:36 -0600
Jim van Wel wrote:
Hi there,
My question is the same. I hear no one here about this matter. Please
respond!
It's stupid, but the bug is known here right?
<snip>
Until a patch comes out, I'd move/rename /etc/httpd/conf.d/php.conf and
restart the httpd service...thereby removing php capability, but
protecting yourself from compromise. At least until RH releases an update.