I've built RPMs of PHP 4.1.2 incorporating Mitel's security patch; they are now available for download at my contrib directory at
ftp://ftp.e-smith.org/pub/e-smith/contrib/DanBrown/RPMS/ IMPORTANT: If you are using my PHP 4.1.1 RPMs, or any version other than that provided by Mitel's latest update blades, you should upgrade to this version to fix a security vulnerability.
My HOWTO has been updated to reflect the new versions.
NOTE:
Mitel's Update1 blade specifically requires their version of PHP. Since I didn't hear any better suggestions on how to handle this fact, these RPMs have an Obsoletes: tag that obsoletes 5.1.2 Update1, 5.1.1 Update1, and 5.0 Update4. This will, I expect, result in those blades showing as "Not Installed" in your blades panel. However, it should also allow my updates to be installed without using the --force or --nodeps flags to RPM.
These RPMs were built by taking the stock PHP 4.1.2 tarball, and applying Mitel's (Charlie's) patch to it without modification. It "works" in that it builds without errors, and the resulting RPMs install and seem to run, but I can't vouch for the effectiveness of the patch in this application. Charlie's written that he doesn't know of any reason that it wouldn't work, but I'm sure he's not willing to guarantee it either. It'd be good if somebody who knew what s/he's doing would take a look at it; that would not be me.
As always, any feedback on these RPMs is appreciated.