Doc #64360 [Opn->Csd]: Premature vulnerability disclosure in changelog

From: Date: Sun, 16 Jun 2013 23:45:37 +0000
Subject: Doc #64360 [Opn->Csd]: Premature vulnerability disclosure in changelog
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-9947@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64360&edit=1 ID: 64360 Updated by: stas@php.net Reported by: sarciszewski at knights dot ucf dot edu Summary: Premature vulnerability disclosure in changelog -Status: Open +Status: Closed Type: Documentation Problem Package: Documentation problem Operating System: Any PHP Version: Irrelevant -Assigned To: +Assigned To: stas Block user comment: N Private report: N New Comment: We'll take it into consideration, thanks. Previous Comments: ------------------------------------------------------------------------ [2013-03-05 19:04:36] sarciszewski at knights dot ucf dot edu Description: ------------ https://github.com/php/php-src/blob/php-5.4.13RC1/NEWS Versus http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1635 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1643 In the future, please do not go into detail for a CVE until the patch is released. Even though you guys know, it might as well be a 0day to me because I run 5.4.12 (current stable). Test script: --------------- N/A Expected result: ---------------- - SOAP . Fixed security bug (CVE-2013-1635). (Dmitry) . Fixed security bug (CVE-2013-1643). (Dmitry) Actual result: -------------- - SOAP . Added check that soap.wsdl_cache_dir conforms to open_basedir (CVE-2013-1635). (Dmitry) . Disabled external entities loading (CVE-2013-1643). (Dmitry) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=64360&edit=1

« previous php.doc.bugs (#9947) next »