Re: CVS Account Request
| From: | Zeev Suraski | Date: | Thu, 16 Nov 2000 10:39:23 +0000 |
| Subject: | Re: CVS Account Request | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-38324@lists.php.net to get a copy of this message | ||
At 12:00 16-11-00, Stanislav Malyshev wrote:
AZ>> > at all. I think an obvious exploit would have gone in just AZ>> fine, as they > did in the past. They can be malicious one day AZ>> as well. AZ>> AZ>> FWIW, I did look at his code, but I did so not really looking for buffer AZ>> overflows. For the record, I regularilly see crash bugs (including overflows) in good old trusted PHP code, and nobody's dead because of that. Things happen, nobody's perfect. So when the thing is seen, we fix it, what else?Death is not the issue here. There weren't too many remotely exploitable holes in PHP, but when one comes out, it *is* bad. Very bad. Zeev -- Zeev Suraski <zeev@zend.com> CTO, Zend Technologies Ltd. http://www.zend.com/