This evening all Mr.Host web servers were upgraded to Apache 2.2.25 and PHP 5.3.27.
Apache 2.2.25
This version of Apache is principally a security and bug fix legacy release, including the following security fixes:
- SECURITY: CVE-2013-1896 (cve.mitre.org) mod_dav: Sending a MERGE request against a URI handled by mod_dav_svn with the source href (sent as part of the request body as XML) pointing to a URI that is not configured for DAV will trigger a segfault.
- SECURITY: CVE-2013-1862 (cve.mitre.org) mod_rewrite: Ensure that client data written to the RewriteLog is escaped to prevent terminal escape sequences from entering the log file.
PHP 5.3.27
- Core:
- DateTime:
- Fixed bug #53437 (Crash when using unserialized DatePeriod instance).
- PDO_firebird:
- PDO_pgsql:
- Fixed bug #64949 (Buffer overflow in _pdo_pgsql_error).
- pgsql:
- Fixed bug #64609 (pg_convert enum type support).
- SPL:
- Fixed bug #64997 (Segfault while using RecursiveIteratorIterator on 64-bits systems).
- XML:
- Fixed bug #65236 (heap corruption in xml parser).