shylocker110 发表于 2015-5-21 12:35:20

PHP5.2和5.3的补丁大牛已放出。就等军哥发打补丁脚本或教程

https://coding.net/u/simapple/p/oldphppatch/git/tree/master/CVE-ID2015-4024

licess 发表于 2015-5-21 14:58:50

php 5.2 修改php升级脚本,查找 patch -p1 < php-5.2.17-max-input-vars.patch
该行下面添加:

wget http://soft.vpser.net/web/php/bug/php-5.2-multipart-form-data.patch
patch -p1 < php-5.2-multipart-form-data.patch


php 5.3查找cd php-$php_version/ 应该是198行,下面添加

wget http://soft.vpser.net/web/php/bug/php-5.3-multipart-form-data.patch
patch -p1 < php-5.3-multipart-form-data.patch

并将
42行到45行
        if [ "$php_version" == "$old_php_version" ]; then
                echo "Error: The upgrade PHP Version is the same as the old Version!!"
                exit 1
        fi
删除


再运行升级脚本,输入当前php版本号

其他php 5.4,、5.5、5.6直接升级即可

灵尘子 发表于 2015-5-21 16:43:07

lnmp安装包是不是也可以修复下这个BUG呢

shijack 发表于 2015-5-24 16:58:09

军哥,按你的提示,使用up重新安装了一次5.2 安装完成后,通过https://portal.nsfocus.com/vulnerability/list/检测发现,漏洞,还存在,又手动编译安装一次,还是提示存在,而你的网站就显示没有这个漏洞?这个怎么搞。。。。

asmon 发表于 2015-5-24 17:09:01

============================check files==================================
Error: php-5.2.17p1.tar.gz not found!!!download now......
--2015-05-24 17:07:18--http://www.php.net/distributions/php-5.2.17p1.tar.gz
Resolving www.php.net (www.php.net)... 72.52.91.14, 2a02:cb41::7
Connecting to www.php.net (www.php.net)|72.52.91.14|:80... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Location: http://php.net/distributions/php-5.2.17p1.tar.gz
--2015-05-24 17:07:18--http://php.net/distributions/php-5.2.17p1.tar.gz
Resolving php.net (php.net)... 72.52.91.14, 2a02:cb41::7
Reusing existing connection to www.php.net:80.
HTTP request sent, awaiting response... 404 Not Found
2015-05-24 17:07:18 ERROR 404: Not Found.

--2015-05-24 17:07:18--http://museum.php.net/php5/php-5.2.17p1.tar.gz
Resolving museum.php.net (museum.php.net)... 104.236.41.219, 2604:a880:800:10::2ce:1
Connecting to museum.php.net (museum.php.net)|104.236.41.219|:80... connected.
HTTP request sent, awaiting response... 404 Not Found
2015-05-24 17:07:18 ERROR 404: Not Found.

WARNING!May be the php version you input was wrong,please check!
PHP Version input was:5.2.17p1


提示错误,直接退出升级了。

licess 发表于 2015-5-24 22:06:49

版本要输入5.2.17

shijack 发表于 2015-5-24 22:10:22

输和是5.2.17这个没错的。也升级好了,就是线上检测,还存在漏洞。

licess 发表于 2015-5-25 10:44:36

回复 7# 的帖子

毕竟不是官方的补丁,从我自己的测试看php 5.2、5.3下基本都能行,但还是有cpu变高的情况
即使是php 5.6在某些情况下也有cpu猛增的现象
页: [1]
查看完整版本: PHP5.2和5.3的补丁大牛已放出。就等军哥发打补丁脚本或教程