Here is what the message in the DSA-3380 said:
Note to users of the oldstable distribution (wheezy): PHP 5.4 has
reached end-of-life on September 14th, 2015. As a result, there will
be no more new upstream releases. The security support of PHP 5.4 in
Debian oldstable (wheezy) will be best effort only, and you are
strongly advised to upgrade to latest Debian stable release (jessie),
which includes PHP 5.6.
The Debian security team keeps your whole system "secure" (as far as that is humanly possible with PHP) by backporting the latest security patches while minimizing incompatibilities. Now there are no official security patches anymore from PHP upstream. So the Debian security team now needs to adapt security updates for higher PHP versions back to PHP 5.4. This probably takes additional time or might not be feasable at all.
So they recommend you to upgrade to Debian "Jessie" 8 (which is the current stable
) as soon as possible. Debian "Wheezy" 7 is oldstable
and should still be supported by the security team. But usually the security team support ends about a year after the stable
release. As Debian "Jessie" 8 has been released on 2015-04-25 the usual year of support might end as soon as in two months from now.
After that there is supposed to be an additional Long Term Support (LTS) support period in which a different team tries to support that distribution for another period of time. According to the LTS wiki page, the LTS team has already taken over the security support of Debian "Wheezy" 7 and will support it until May 2018.
So to profit from the Debian maintenance to keep your whole system secure, you should probably upgrade to Debian "Jessie" 8 as soon as possible. Maintaining the security of software on your own is far more time consuming than upgrading your system once every few years, at least in my experience.