Re: Re: cvs: php4(PHP_4_0_5) /sapi/fastcgi
| From: | Andi Gutmans | Date: | Wed, 21 Mar 2001 18:58:55 +0000 |
| Subject: | Re: Re: cvs: php4(PHP_4_0_5) /sapi/fastcgi | ||
| References: | 1 | Groups: | php.dev php.qa |
| Request: | Send a blank email to php-dev+get-49657@lists.php.net to get a copy of this message | ||
Why do we need to have an interrogation. Relax, it's not such a big deal.
4.0.4pl1 & 4.0.3pl1 both had security fixes (Apache config handling was a security issue).
Anyway, I still don't understand what the big fuss is about. Let's stop arguing about this like 4th graders.
By the way, the error_reporting() pl1 in 4.0.1 was due to a bug which was in the CVS a looooong time. It was not a spontaneous bug that was introduced.
Andi
At 07:50 PM 3/21/2001 +0100, Sascha Schumann wrote:
On Wed, 21 Mar 2001, Andi Gutmans wrote: A couple of these were buffer overflows IIRC which were security issues. Remember the group@ emails about those?Fixes against format-string attacks and for file-upload issues went into 4.0.3. Or what are you referring to?- Sascha Experience IRCG http://schumann.cx/ http://schumann.cx/ircg