Security Audit 4.0.7RC2
| From: | Hellekin O. Wolf | Date: | Mon, 10 Sep 2001 14:17:47 +0000 |
| Subject: | Security Audit 4.0.7RC2 | ||
| Groups: | php.dev php.qa | ||
| Request: | Send a blank email to php-dev+get-65659@lists.php.net to get a copy of this message | ||
Hello people,
this is a security audit of PHP-4.0.7RC2 (4.0.6 is also available) where you can find :
- Potential threats such as buffer Overflows, Race Conditions, Format Strings and Temporary files.
- Which functions are dangerous and how to replace them.
- Where (files and lines) you can find them.
The software behind that audit reads C source code to find selected patterns.
It is currently under development. Thanks to Philippe Langlois for providing the audit and code.
The results do not mean there *is* a flaw, but that corrections may be implemented to avoid such flaws.
http://hellekin.multimania.com/hitscore.php
(This is temporary URL. Do not bookmark nor forward).
how