PHP 5.4 is dead
+
Par Remi le lundi 5 octobre 2015, 08:24 - HowTo - Lien permanent
As announced, PHP version 5.4.45 is the last official release of PHP 5.4
Which means that since version 5.5.30 and version 5.6.14 have been released, some security vulnerabilities are not, and won't be, fixed by the PHP project.
To keep a secure installation, the upgrade to a maintained version is strongly recommended:
- PHP 5.5 is in security support mode only (no other bug will be fixed) until July 2016.
- PHP 5.6 is in active support mode, and will be maintained until
August 2017December 2018. - PHP 7.0 is in under development, in stabilization phase (Release Candidate) and should be released as stable quite soon.
Read :
- PHP Supported versions
- Migration guide from PHP 5.4.x to PHP 5.5.x
- Migration guide from PHP 5.5.x to PHP 5.6.x
- Migration guide from PHP 5.6.x to PHP 7.0.x
However, given the very important number of downloads by the users of my repository (~47%) the version is still available in remi repository for Enterprise Linux (RHEL, CentOS...) and Fedora (Software Collections) and includes the latest security fix.
Warning : this is a best effort action, depending of my spare time, without any warranty, only to give users more time to migrate. This can only be temporary, and upgrade must be the priority.
Commentaires
Version 5.4.45-1 is still 47% of downloads (5.5.29: 21%, 5.6.13: 31%).
Version 5.4.45-2 includes fix for bugs #70433 and #69720 (backported from 5.5.30).
Base packages (php)
Software Collections (php54)
Version 5.4.45-3 includes fix for bugs #70755, #70728, #70741 and #70661 (backported from 5.5.31).
Base packages (php)
Software Collections (php54)
Version 5.4.45-4 includes security fix for bugs #71354 #71335 #71391 #71323 #71459 #71039 #71720 et #71488 (backported from 5.5.32).
Base packages (php)
Software Collections (php54)
Version 5.4.45-5 includes security fix for bugs #71498 and #71587 (backported from 5.5.33).
Base packages (php)
Software Collections (php54)
Version 5.4.45-5 is still 33% of downloads (5.5.33: 19%, 5.6.19: 41%, 7.0.4: 7%). Still too much.
Version 5.4.45-7 includes security fix for bugs #71906, #71798, #71860, #71704 and #71527 (backported from 5.5.34).
Base packages (php)
Software Collections (php54)
Version 5.4.45-8 includes security fix for bugs #649.8, #71912, #72061, #72093, #72094 and #72099 (backported from 5.5.35).
Base packages (php)
Software Collections (php54)
Version 5.4.45-8 is still 30% of downloads (5.5.35: 21%, 5.6.21: 40%, 7.0.4: 9%). Still too much.
Version 5.4.45-9 includes security fix for bugs #72241, #72114, #72135 and #71331 (backported from 5.5.36).
Base packages (php)
Software Collections (php54)
Version 5.4.45-9 is still 35.5% of downloads (5.5.35:17.8%, 5.6.21:37.2%, 7.0.6:9.4%). Still really too much.
Version 5.4.45-10 includes security fix for bugs #72241, #72241, #72241, #72241, #72241, #72241, #72241, #72241, #72241, #72241, #72114, #72135 and #71331 (backported from 5.5.37).
Base packages (php)
Software Collections (php54)
Version 5.4.45-10 is still 38.2% of downloads (5.5.35:16.1%, 5.6.21:34.5%, 7.0.6:11.2%). Still really too much.
Version 5.4.45-10 includes security fix for bugs #72613, #70480, #72513, #72562, #72573, #72603, #72618, #72519, #72533, #69975, #72479, #72606 and #72520 (backported from 5.5.38).
Base packages (php)
Software Collections (php54)
Version 5.4.45-12 includes "some" security fix backported from 5.6.26.
Base packages (php)
Software Collections (php54)
The security patches in 5.6.27 don't worth to be backported, as they only involved big strings (2GB) and so a decent memory_limit is enough to be safe.
Version 5.4.45-13 includes "some" security fix backported from 5.6.30.
Base packages (php)
Software Collections (php54)
Version 5.4.45-14 includes 6 security fix backported from 5.6.
Base packages (php)
Software Collections (php54)
Version 5.4.45-15 includes 1 security fix backported from 5.6.38 (mod_php)
Base packages (php)
Software Collections (php54)
Version 5.4.45-16 includes 3 security fix backported from 5.6.39 (imap and filter)
Base packages (php)
Software Collections (php54)
Version 5.4.45-17 includes 2 security fix backported from 5.6.40 (xmlrpc)
Base packages (php)
Software Collections (php54)
As I now also maintain version 5.6 and 7.0, The older versions (5.4 and 5.5) will only receive the critical securtity fix.
Version 5.4.45-18 includes 1 security fix backported from 7.1.33 (fpm)
Base packages (php)
Software Collections (php54)
Version 5.4.45-19 includes 1 security fix backported from 7.4.30 (mysql)
Base packages (php)
Software Collections (php54)