PHP 4.3.2 Released
seldo writes "Everyone's favourite scripting language ;-) has released an update. From their site: 'The PHP developers are proud to announce the immediate availability of PHP 4.3.2. This release contains a huge number of bug fixes and is a strongly recommended update for all users of PHP. Full list of fixes can be found in the NEWS file.' This incremental release also has useful additions, such as updating to support GD 2.0.12."
What's the official word on Apache 2.0 support? Do they still recommend that you use Apache 1.x for now?
I combed through the changenotes and here are the ones that I thought were among the most important:
# Added a new Apache 2 SAPI module (apache2handler) based on the old version (apache2filter).
# Fixed several 64-bit problems
# Fixed bug #22672 (User not logged under Apache2). (Ian)
# Fixed bug #22989 (sendmail not found by configure). (igyu@ionsphere.org)
# Fixed bug #17098 (make Apache2 aware that PHP scripts should not be cached). (Ilia)
# Fixed bug #20802 (PHP would die silently when memory limit reached). (Ilia)
# Fixed bug #21498 (mysql_pconnect connection problems). (Georg)
http://tinyurl.com/4ny52
The same might be said for C. How many inexperienced C programmers have you seen do something like this:
#include <string.h>
int main(int argc, char *argv[])
{
char buffer[1024];
if (argc > 1)
{
strcpy(buffer, argv[1]);
}
return 0;
}
register_globals was never a good idea. That's why it's been off by default for the past several releases. Unless you're using placeholders in your SQL, nearly every Web app has the potential to be susceptable to bad things:
$db->execute("SELECT * FROM my_table WHERE id = $userInput");
vs.
$db->execute('SELECT * FROM my_table WHERE id =
This is not limited to the 'Nukes or PHP. Perl, Python, C, Java, etc. all suffer from the same problem.
moto411.com
People still use perl? I thought it died in the big explosion at the punctuation factory....
You'll have that sometimes...