Re: [BUG]vulnerabilities in PHP's file uploadcode - still uncovered in 4.1.2
| From: | derick@php.net | Date: | Tue, 19 Mar 2002 10:41:41 +0000 |
| Subject: | Re: [BUG]vulnerabilities in PHP's file uploadcode - still uncovered in 4.1.2 | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-81489@lists.php.net to get a copy of this message | ||
On Tue, 19 Mar 2002, Stefan Esser wrote:
>
> Ehmm there is one thing that makes it more serious than the other crash
> bugs:
> its remotely triggerable.
I know, but I still don't think it warrants 4.1.3 :)
> But honestly i doubt a kiddie will use this bug to dos a server. Apache will
> respawn all its childs anyway and for the kids its much easier to use
> their stupid smurf or whatever tools, than to send malformed fileuploads.
Derick
-----------------------------------------------------------------------
PHP: Scripting the Web - derick@php.net
All your branches are belong to me!
SRM: Script Running Machine - www.vl-srm.net
-----------------------------------------------------------------------