3 ms·
PHP minor releases are bug and security fixes. But as long as the latest minor release fixed a vulnerability, in 99% of the cases, you can assume that all previ
by Rygu 12y ago
PHP minor releases are bug and security fixes. But as long as the latest minor release fixed a vulnerability, in 99% of the cases, you can assume that all previous versions contain that vulnerability. (I know, I know, regressions do happen)
- xyby 12y agoYes. But does every minor release fix bugs AND security holes? If some only fix bugs, the equation "not newest = insecure" is wrong.
- ircmaxell 12y agoI counted any point release since the latest security release as secure. So for PHP's 5.6 line, only 5.6.4 is secure, since 5.6.4 is a security release. I'm currently crunching numbers for other platforms. For example, Nginx's last security release (for 1.7) was 1.7.5, so 1.7.5 -> 1.7.9 are all considered security.
- lstamour 12y agoYou can see a list of vulnerable PHP versions here: http://www.cvedetails.com/version-list/74/128/1/PHP-PHP.html http://www.cvedetails.com/version-list/74/128/1/PHP-PHP.html Note that this list refers to those versions as released, not as OS vendors may have patched them.
- TylerE 12y agoIt's PHP. Fingers in the dike. But don't take my word for it... http://php.net/ChangeLog-5.php http://php.net/ChangeLog-5.php At least 90% of releases have a bugfix with an associated CVE vulnerability.