Re: Mitigate “Magellan vulnerabil itites” in PHP 7.2?
| From: | Christoph M. Becker | Date: | Mon, 11 Mar 2019 16:35:23 +0000 |
| Subject: | Re: Mitigate “Magellan vulnerabil itites” in PHP 7.2? | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-104659@lists.php.net to get a copy of this message | ||
On 19.02.2019 at 02:16, Stanislav Malyshev wrote:
>> In my opinion, adding this ini setting to PHP-7.4 is a no brainer, but I
>> suggest that we backport it to PHP-7.2 as well.
>
> I don't see a reason why not - if the option is useful for improving
> security/stability, let's backport it. If it's security related, maybe
> even to 7.1 since it's still in security support (if it's not too hard).
I have applied the PR[1] to PHP-7.2+. Joe may consider to cherry-pick
to 7.1.
[1] <https://github.com/php/php-src/pull/3709>
--
Christoph M. Becker