On Wed, 2010-12-01 at 13:50 +0100, Leonard den Ottolander wrote:
All these vulnerabilities except for the last one (https://www.redhat.com/security/data/cve/CVE-2010-3870.html / http://bugs.php.net/bug.php?id=49687) are fixed in PHP-5.2.14. For this one issue you might need to use the patch from the latest upstream SRPM.
http://svn.php.net/viewvc/php/php-src/branches/PHP_5_2/ext/xml/xml.c?r1=2931... is the fix for the 5.2 branch which is not yet in the released 5.2.14.