So is it just me, or is this a total release management failure that there can be multiple different things called "PHP 5.3.3" (or any other version number), which behave differently, some of which have security vulnerabilities and some don't.
If you want to know if you are vulnerable or not, knowing you have "PHP 5.3.3" is not enough -- I'm not even sure how you'd tell if you had a patched version or a non-patched version, other than testing it for vulnerability.
Something seems horribly wrong here, no?