The following errata for CentOS-2 have been built and uploaded the the centos mirror:
RHSA-2004:395-01 Updated php packages fix security issues
Files available: php-4.1.2-2.1.8.i386.rpm: php-devel-4.1.2-2.1.8.i386.rpm: php-imap-4.1.2-2.1.8.i386.rpm: php-ldap-4.1.2-2.1.8.i386.rpm: php-manual-4.1.2-2.1.8.i386.rpm: php-mysql-4.1.2-2.1.8.i386.rpm: php-odbc-4.1.2-2.1.8.i386.rpm: php-pgsql-4.1.2-2.1.8.i386.rpm:
More details are available from the RedHat web site at https://rhn.redhat.com/errata/rh21as-errata.html
php modules from extras will be available soon.
The easy way to make sure you are up to date with all the latest patches is to run: # yum update