<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Dotdeb</title>
	<atom:link href="http://www.dotdeb.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dotdeb.org</link>
	<description>The repository for Debian-based LAMP servers</description>
	<lastBuildDate>Tue, 09 Mar 2010 12:21:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>PHP 5.3.2 is available too!</title>
		<link>http://www.dotdeb.org/2010/03/08/php-5-3-2-is-available-too/</link>
		<comments>http://www.dotdeb.org/2010/03/08/php-5-3-2-is-available-too/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 22:29:56 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHP5]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=340</guid>
		<description><![CDATA[A few days ago, the PHP Group released PHP 5.3.2. It fixes severe security issues and some other bugs :
The PHP development team is proud to announce the immediate release of PHP 5.3.2. This is a maintenance release in the 5.3 series, which includes a large number of bug fixes.
Security Enhancements and Fixes in PHP [...]]]></description>
			<content:encoded><![CDATA[<p>A few days ago, the PHP Group released PHP 5.3.2. It fixes severe security issues and some other bugs :</p>
<blockquote><p>The PHP development team is proud to announce the immediate release of PHP 5.3.2. This is a maintenance release in the 5.3 series, which includes a large number of bug fixes.</p>
<p><strong>Security Enhancements and Fixes in PHP 5.3.2:</strong></p>
<ul>
<li>Improved LCG entropy. (Rasmus, Samy Kamkar)</li>
<li>Fixed safe_mode validation inside tempnam() when the directory path does not end with a /). (Martin Jansen)</li>
<li>Fixed a possible open_basedir/safe_mode bypass in the session extension identified by Grzegorz Stachowiak. (Ilia)</li>
</ul>
<p>(&#8230;)</p></blockquote>
<p>It is now available on Dotdeb (still on <a title="PHP 5.3 Dotdeb repository" href="http://php53.dotdeb.org/">a separate repository</a>) with the following changes :</p>
<ul>
<li>id3 and mailparse PECL extensions have been removed from the repository. If some of them were useful to you, please let me know. Don&#8217;t forget that there&#8221;s an easy way to <a title="How to package PECL extensions by yourself" href="http://www.dotdeb.org/2008/09/25/how-to-package-php-extensions-by-yourself/">package PECL extensions by yourself</a></li>
<li><a title="How to package PECL extensions by yourself" href="http://www.dotdeb.org/2008/09/25/how-to-package-php-extensions-by-yourself/"></a>the memcache extension has been downgraded to v3.0.3 because of a <a title="PECL bug #16061" href="http://pecl.php.net/bugs/bug.php?id=16061">bug in the session redundancy</a></li>
<li>php5-fpm is now an alternative dependency og the php5 meta-package</li>
</ul>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-341" title="ElePHPant v3.0" src="http://www.dotdeb.org/wp-content/uploads/2010/03/elephpant_281_193.png" alt="" width="281" height="193" /></p>
<p>As usual, please read <a title="PHP 5.3.2 release announcement" href="http://www.php.net/archive/2010.php#id2010-03-04-1">the release announcement</a> and the full <a title="The PHP5 Changelog" href="http://www.php.net/ChangeLog-5.php#5.3.2">Changelog</a> before upgrading. If you&#8217;re migrating from PHP 5.2, you can also take a look at <a title="from PHP 5.2 to PHP 5.3 migration guide" href="http://www.php.net/migration53">migration guide</a>.</p>
<p><strong>[Update]</strong> The packages have been updated to fix <a title="PHP bug #51242" href="http://bugs.php.net/51242">a MySQL connection issue</a>. The geoip PECL extension is back.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/03/08/php-5-3-2-is-available-too/feed/</wfw:commentRss>
		<slash:comments>22</slash:comments>
		</item>
		<item>
		<title>PHP 5.2.13 is available</title>
		<link>http://www.dotdeb.org/2010/03/07/php-5-2-13-is-available/</link>
		<comments>http://www.dotdeb.org/2010/03/07/php-5-2-13-is-available/#comments</comments>
		<pubDate>Sun, 07 Mar 2010 12:21:41 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHP5]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=336</guid>
		<description><![CDATA[A few days ago, the PHP Group released PHP 5.2.13. It fixes severe security issues and some other bugs :
The PHP development team would like to announce the immediate availability of PHP 5.2.13. This release focuses on improving the stability of the PHP 5.2.x branch with over 40 bug fixes, some of which are security [...]]]></description>
			<content:encoded><![CDATA[<p>A few days ago, the PHP Group released PHP 5.2.13. It fixes severe security issues and some other bugs :</p>
<blockquote><p>The PHP development team would like to announce the immediate availability of PHP 5.2.13. This release focuses on improving the stability of the PHP 5.2.x branch with over 40 bug fixes, some of which are security related. All users of PHP 5.2 are encouraged to upgrade to this release.</p>
<p><strong>Security Enhancements and Fixes in PHP 5.2.13:</strong></p>
<ul>
<li>Fixed safe_mode validation inside tempnam() when the directory path does not end with a /). (Martin Jansen)</li>
<li>Fixed a possible open_basedir/safe_mode bypass in the session extension identified by Grzegorz Stachowiak. (Ilia)</li>
<li>Improved LCG entropy. (Rasmus, Samy Kamkar)</li>
</ul>
<p>(&#8230;)</p></blockquote>
<p>On the Dotdeb side</p>
<ul>
<li>geoip, id3 and mailparse PECL extensions have been removed from the repository. If some of them were useful to you, please let me know. Don&#8217;t forget that there&#8221;s an easy way to <a title="How to package PECL extensions by yourself" href="http://www.dotdeb.org/2008/09/25/how-to-package-php-extensions-by-yourself/">package PECL extensions by yourself</a></li>
<li><a title="How to package PECL extensions by yourself" href="http://www.dotdeb.org/2008/09/25/how-to-package-php-extensions-by-yourself/"></a>the memcache extension has been downgraded to v3.0.3 because of a <a title="PECL bug #16061" href="http://pecl.php.net/bugs/bug.php?id=16061">bug in the session redundancy</a>.</li>
</ul>
<p>As usual, please read <a title="PHP 5.2.13 release announcement" href="http://www.php.net/releases/5_2_13.php">the release announcement</a> and the full <a title="The PHP5 Changelog" href="http://www.php.net/ChangeLog-5.php#5.2.13">Changelog</a> before upgrading.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/03/07/php-5-2-13-is-available/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>MySQL 5.1.44 is available for Debian 5.0 &#8220;Lenny&#8221;</title>
		<link>http://www.dotdeb.org/2010/02/21/mysql-5-1-44-is-available-for-debian-5-0-lenny/</link>
		<comments>http://www.dotdeb.org/2010/02/21/mysql-5-1-44-is-available-for-debian-5-0-lenny/#comments</comments>
		<pubDate>Sun, 21 Feb 2010 00:16:09 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[MySQL]]></category>
		<category><![CDATA[MySQL 5.1]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=334</guid>
		<description><![CDATA[MySQL 5.1.44 is now available on Dotdeb for Debian 5.0 “Lenny” in amd64/i386 flavours.
This is primarily a bug fix release, but please read the Changelog carefully before upgrading.
]]></description>
			<content:encoded><![CDATA[<p>MySQL 5.1.44 is now available on Dotdeb for Debian 5.0 “Lenny” in amd64/i386 flavours.</p>
<p>This is primarily a bug fix release, but please read the <a title="List of changes in MySQL 5.1.44" href="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-44.html">Changelog</a> carefully before upgrading.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/02/21/mysql-5-1-44-is-available-for-debian-5-0-lenny/feed/</wfw:commentRss>
		<slash:comments>17</slash:comments>
		</item>
		<item>
		<title>MySQL 5.1.43 is available for Debian &#8220;Lenny&#8221; (and &#8220;Etch&#8221;&#8230;)</title>
		<link>http://www.dotdeb.org/2010/02/04/mysql-5-1-43-is-available-for-debian-lenny-and-etch/</link>
		<comments>http://www.dotdeb.org/2010/02/04/mysql-5-1-43-is-available-for-debian-lenny-and-etch/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 15:56:55 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[MySQL]]></category>
		<category><![CDATA[MySQL 5.1]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=327</guid>
		<description><![CDATA[MySQL 5.1.43 is now available on Dotdeb for Debian 5.0 “Lenny” / Debian 4.0 “Etch” in amd64/i386 flavours.
Please note that it&#8217;s the last update for Etch, because the security supports ends for this branch (time to upgrade!).
This maintenance release comes with many improvements and bugfixes, especially the InnoDB plugin 1.0.6 (please read the Changelog for [...]]]></description>
			<content:encoded><![CDATA[<p>MySQL 5.1.43 is now available on Dotdeb for Debian 5.0 “Lenny” / Debian 4.0 “Etch” in amd64/i386 flavours.</p>
<p>Please note that it&#8217;s the last update for Etch, because <a title="End of security support for Etch" href="http://www.dotdeb.org/2010/01/20/etch-security-support-discontinued-by-debian-on-feb-15th/">the security supports ends</a> for this branch (time to upgrade!).</p>
<p>This maintenance release comes with many improvements and bugfixes, especially the InnoDB plugin 1.0.6 (please read the <a title="List of changes in MySQL 5.1.43" href="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-43.html">Changelog</a> for more details).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/02/04/mysql-5-1-43-is-available-for-debian-lenny-and-etch/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Etch security support discontinued by Debian on Feb. 15th&#8230;</title>
		<link>http://www.dotdeb.org/2010/01/20/etch-security-support-discontinued-by-debian-on-feb-15th/</link>
		<comments>http://www.dotdeb.org/2010/01/20/etch-security-support-discontinued-by-debian-on-feb-15th/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 21:33:02 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[Etch]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Squeeze]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=319</guid>
		<description><![CDATA[The Debian security team announced that Debian 4.0 &#8220;Etch&#8221; security support  will be ended on February 15th, 2010 :

Security Support for Debian GNU/Linux 4.0 to be discontinued on
February 15th

One year after the release of Debian GNU/Linux 5.0 alias 'lenny' and
nearly three years after the release of Debian GNU/Linux 4.0 alias
'etch' the security support for the [...]]]></description>
			<content:encoded><![CDATA[<p>The Debian security team <a title="Debian 4.0 &quot;Etch&quot; security support ended on Feb. 15th, 2010" href="http://lists.debian.org/debian-security-announce/2010/msg00010.html">announced</a> that Debian 4.0 &#8220;Etch&#8221; security support  will be ended on February 15th, 2010 :</p>
<blockquote>
<pre>Security Support for Debian GNU/Linux 4.0 to be discontinued on
February 15th

One year after the release of Debian GNU/Linux 5.0 alias 'lenny' and
nearly three years after the release of Debian GNU/Linux 4.0 alias
'etch' the security support for the old distribution (4.0 alias
'etch') is coming to an end next month.  The Debian project is proud
to be able to support its old distribution for such a long time and
even for one year after a new version has been released.

The Debian project has released Debian GNU/Linux 5.0 alias 'lenny' on
the 14th of February 2009.  Users and Distributors have been given a
one-year timeframe to upgrade their old installations to the current
stable release.  Hence, the security support for the old release of
4.0 is going to end in February 2010 as previously announced.

Previously announced security updates for the old release will continue
to be available on security.debian.org.</pre>
</blockquote>
<p>Then, Dotdeb will follow the Debian project and all the Etch packages will be moved to <a title="the Dotdeb archives" href="http://archives.dotdeb.org/">http://archives.dotdeb.org/</a> on Feb. 15th.</p>
<p>It is now time for you to upgrade your last servers from Etch to Lenny&#8230;</p>
<h2>What&#8217;s next?</h2>
<p>I&#8217;ll have to prepare the <a title="Debian Squeeze" href="http://www.debian.org/releases/squeeze/">Squeeze</a> release (planned on August 2010). The (early) plans ?</p>
<ul>
<li>Focus on high quality PHP 5.3 and MySQL 5.1+ packages</li>
<li>More useful tools for your LAMP platforms : Gearman, Maatkit&#8230; MariaDB? Drizzle? Wait &amp; see</li>
<li>No more mail-realated packages (Qmail, Vpopmail, Courier, Dovecot, Vqadmin)</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/01/20/etch-security-support-discontinued-by-debian-on-feb-15th/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>MySQL 5.1.41 has been updated to fix a security issue</title>
		<link>http://www.dotdeb.org/2010/01/20/mysql-5-1-41-has-been-updated-to-fix-a-security-issue/</link>
		<comments>http://www.dotdeb.org/2010/01/20/mysql-5-1-41-has-been-updated-to-fix-a-security-issue/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 20:25:13 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[MySQL]]></category>
		<category><![CDATA[MySQL 5.1]]></category>
		<category><![CDATA[release]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=317</guid>
		<description><![CDATA[I just uploaded new MySQL 5.1.41 packages that fix a remote buffer overflow in MySQL servers that use the embedded YaSSL library :

Lenz Grimmer gives more information about this issue
CVE-2009-4484 has been filled

Since Debian and Dotdeb are impacted, you are strongly encouraged to upgrade your servers.
]]></description>
			<content:encoded><![CDATA[<p>I just uploaded new MySQL 5.1.41 packages that fix a remote buffer overflow in MySQL servers that use the embedded YaSSL library :</p>
<ul>
<li>Lenz Grimmer <a title="remote security vulnerability in MySQL 5.x" href="http://lists.mysql.com/packagers/444">gives more information</a> about this issue</li>
<li><a title="CVS-2009-4484" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4484">CVE-2009-4484</a> has been filled</li>
</ul>
<p>Since Debian and Dotdeb are impacted, you are strongly encouraged to upgrade your servers.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/01/20/mysql-5-1-41-has-been-updated-to-fix-a-security-issue/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Dotdeb interviewed by PHP TV</title>
		<link>http://www.dotdeb.org/2010/01/20/dotdeb-interviewed-by-php-tv/</link>
		<comments>http://www.dotdeb.org/2010/01/20/dotdeb-interviewed-by-php-tv/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 08:46:55 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[dotdeb]]></category>
		<category><![CDATA[interview]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=312</guid>
		<description><![CDATA[Just for fun : I&#8217;ve been interviewed about Dotdeb by PHP TV, a french-speaking webTV.

]]></description>
			<content:encoded><![CDATA[<p>Just for fun : I&#8217;ve been interviewed about Dotdeb by <a title="PHP TV" href="http://www.phptv.fr/">PHP TV</a>, a french-speaking webTV.</p>
<div><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="365" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://www.dailymotion.com/swf/xbwtee&amp;related=0" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="480" height="365" src="http://www.dailymotion.com/swf/xbwtee&amp;related=0" allowscriptaccess="always" allowfullscreen="true"></embed></object></div>
]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/01/20/dotdeb-interviewed-by-php-tv/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>PHP 5.2.12 packages are here!</title>
		<link>http://www.dotdeb.org/2010/01/11/php-5-2-12-packages-are-here/</link>
		<comments>http://www.dotdeb.org/2010/01/11/php-5-2-12-packages-are-here/#comments</comments>
		<pubDate>Mon, 11 Jan 2010 21:49:56 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHP5]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=310</guid>
		<description><![CDATA[On December 17th 2009, the PHP Group released PHP 5.2.12 :
The PHP development team would like to announce the immediate availability of PHP 5.2.12. This release focuses on improving the stability of the PHP 5.2.x branch with over 60 bug fixes, some of which are security related. All users of PHP 5.2 are encouraged to [...]]]></description>
			<content:encoded><![CDATA[<p>On December 17th 2009, the PHP Group released PHP 5.2.12 :</p>
<blockquote><p>The PHP development team would like to announce the immediate availability of PHP 5.2.12. This release focuses on improving the stability of the PHP 5.2.x branch with over 60 bug fixes, some of which are security related. All users of PHP 5.2 are encouraged to upgrade to this release.</p>
<p><strong>Security Enhancements and Fixes in PHP 5.2.12:</strong></p>
<ul>
<li>Fixed a safe_mode bypass in tempnam() identified by Grzegorz Stachowiak. (CVE-2009-3557, Rasmus)</li>
<li>Fixed a open_basedir bypass in posix_mkfifo() identified by Grzegorz Stachowiak. (CVE-2009-3558, Rasmus)</li>
<li>Added &#8220;max_file_uploads&#8221; INI directive, which can be set to limit the number of file uploads per-request to 20 by default, to prevent possible DOS via temporary file exhaustion, identified by Bogdan Calin. (CVE-2009-4017, Ilia)</li>
<li>Added protection for $_SESSION from interrupt corruption and improved &#8220;session.save_path&#8221; check, identified by Stefan Esser. (CVE-2009-4143, Stas)</li>
<li>Fixed bug #49785 (insufficient input string validation of htmlspecialchars()). (CVE-2009-4142, Moriyoshi, hello at iwamot dot com)</li>
</ul>
</blockquote>
<p>(Please read <a title="PHP 5.2.12 full announcement" href="http://www.php.net/releases/5_2_12.php">the full announcement</a> for more details)</p>
<p>Dotdeb packages of PHP 5.2.12 are now (finally) available for Debian &#8220;Lenny&#8221; and &#8220;Etch&#8221;, amd64 and i386.</p>
<p>Upgrading your servers is strongly encouraged because of several security issue, especially a <a title="multipart/form-data DoS" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4017">multipart/form-data DoS (CVE-2009-4017)</a>. Please set the <a title="the max_file_uploads parameter documentation" href="http://fr.php.net/manual/en/ini.core.php#ini.max-file-uploads">max_file_uploads</a> parameter carefully.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2010/01/11/php-5-2-12-packages-are-here/feed/</wfw:commentRss>
		<slash:comments>19</slash:comments>
		</item>
		<item>
		<title>The PHP 5.3.1 packages have been updated</title>
		<link>http://www.dotdeb.org/2009/12/06/the-php-5-3-1-packages-have-been-updated/</link>
		<comments>http://www.dotdeb.org/2009/12/06/the-php-5-3-1-packages-have-been-updated/#comments</comments>
		<pubDate>Sun, 06 Dec 2009 10:14:09 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHP5]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=304</guid>
		<description><![CDATA[The PHP 5.3.1 packages for Debian &#8220;Lenny&#8221; have been updated to fix :

the php5-fpm binary
the /etc/init.d/php5-fpm script

All should work fine now.
]]></description>
			<content:encoded><![CDATA[<p>The PHP 5.3.1 packages for Debian &#8220;Lenny&#8221; have been updated to fix :</p>
<ul>
<li>the php5-fpm binary</li>
<li>the /etc/init.d/php5-fpm script</li>
</ul>
<p>All should work fine now.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2009/12/06/the-php-5-3-1-packages-have-been-updated/feed/</wfw:commentRss>
		<slash:comments>25</slash:comments>
		</item>
		<item>
		<title>PHP 5.3.1 packages for Debian &#8220;Lenny&#8221; : they&#8217;re here!</title>
		<link>http://www.dotdeb.org/2009/11/30/php-5-3-1-packages-for-debian-lenny-theyre-here/</link>
		<comments>http://www.dotdeb.org/2009/11/30/php-5-3-1-packages-for-debian-lenny-theyre-here/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 08:58:33 +0000</pubDate>
		<dc:creator>Guillaume Plessis</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[PHP5]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.dotdeb.org/?p=300</guid>
		<description><![CDATA[The official announcement
A few days ago, the PHP Group released PHP 5.3.1 :
The PHP development team would like to announce the immediate availability of PHP 5.3.1. This release focuses on improving the stability of the PHP 5.3.x branch with over 100 bug fixes, some of which are security related. All users of PHP are encouraged [...]]]></description>
			<content:encoded><![CDATA[<h3>The official announcement</h3>
<p>A few days ago, the PHP Group released PHP 5.3.1 :</p>
<blockquote><p>The PHP development team would like to announce the immediate availability of PHP 5.3.1. This release focuses on improving the stability of the PHP 5.3.x branch with over 100 bug fixes, some of which are security related. All users of PHP are encouraged to upgrade to this release.</p>
<p><strong>Security Enhancements and Fixes in PHP 5.3.1:</strong></p>
<ul>
<li>Added &#8220;max_file_uploads&#8221; INI directive, which can be set to limit the number of file uploads per-request to 20 by default, to prevent possible DOS via temporary file exhaustion.</li>
<li>Added missing sanity checks around exif processing.</li>
<li>Fixed a safe_mode bypass in tempnam().</li>
<li>Fixed a open_basedir bypass in posix_mkfifo().</li>
<li>Fixed failing safe_mode_include_dir.</li>
</ul>
<p>Further details about the PHP 5.3.1 release can be found in the <a href="http://www.php.net/releases/5_3_1.php">release announcement</a>, and the full list of changes are available in the <a href="http://www.php.net/ChangeLog-5.php#5.3.1">ChangeLog</a>.</p></blockquote>
<p style="text-align: center;"><a title="SpeedHog by rdohms, on Flickr" href="http://www.flickr.com/photos/rdohms/4103030160/"><img class="aligncenter" src="http://farm3.static.flickr.com/2735/4103030160_e28bc28a93.jpg" alt="SpeedHog" width="500" height="375" /></a></p>
<h3>The Dotdeb changes</h3>
<p>On the Debian side, some changes were made :</p>
<ul>
<li>the packages are now patched with the official <a title="the Suhosin project" href="http://www.suhosin.org/">Suhosin</a> patch.</li>
<li>beside the apache2, apache2filter, CGI and CLI flavours, the <a title="the PHP-FPM project" href="http://php-fpm.org/about/">FPM</a> one has now its own dedicated package, named &#8220;php5-fpm&#8221;. It will allow you to have greater performances and a lot of more features on a CGI-style installation (FYI, an init script, a config file and a nginx config sample are provided).</li>
</ul>
<h3 style="font-size: 16px; font-weight: 700; padding: 0px; margin: 0px;">How to install?</h3>
<p>Because <a title="The official PHP documentation about migrating from PHP 5.2 to PHP 5.3" href="http://www.php.net/manual/migration53.php">migrating from PHP 5.2. to PHP 5.3</a> can break some applications, here is the Dotdeb release policy :</p>
<ul>
<li>PHP 5.2 is still the default branch for Debian Lenny for some weeks/months. PHP 5.3 packages are kept on a separate repository.</li>
<li>PHP 5.3 will be the default branch for the upcoming Debian Squeeze (mid-2010)</li>
</ul>
<p>Then , to install PHP 5.3 on your Debian &#8220;Lenny&#8221; box, just add these two entries in your <em>/etc/apt/sources.list</em> :</p>
<pre>deb http://php53.dotdeb.org stable all
deb-src http://php53.dotdeb.org stable all</pre>
<p>Now launch your favorite commands (<tt>apt-get update &amp;&amp; apt-get upgrade</tt>) to upgrade your box.</p>
<p>In case you enjoy this new release, feel free to <a title="Make a Dotdeb donation" href="https://www.paypal.com/xclick/business=gui%40moolfreet.com&amp;item_name=Dotdeb+Donation&amp;no_shipping=1&amp;no_note=1&amp;tax=0&amp;currency_code=EUR&amp;lc=us">donate</a> or to take a look at <a title="my Amazon.fr whishlist" href="http://www.amazon.fr/exec/obidos/registry/1OSKRT7G1UAPW/ref%3Dwl%5Fs%5F3/402-0961397-1287315">my whishlist</a>&#8230; Xmas is coming <img src='http://www.dotdeb.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.dotdeb.org/2009/11/30/php-5-3-1-packages-for-debian-lenny-theyre-here/feed/</wfw:commentRss>
		<slash:comments>67</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 0.324 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2010-03-12 05:45:41 -->
