Re: Mitigate “Magellan vulnerabilitites ” in PHP 7.2?
| From: | Joe Watkins | Date: | Mon, 11 Mar 2019 17:02:28 +0000 |
| Subject: | Re: Mitigate “Magellan vulnerabilitites ” in PHP 7.2? | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-104660@lists.php.net to get a copy of this message | ||
Cheery picked into 7.1
Cheers
Joe
On Mon, 11 Mar 2019 at 17:35, Christoph M. Becker <cmbecker69@gmx.de> wrote:
> On 19.02.2019 at 02:16, Stanislav Malyshev wrote:
>
> >> In my opinion, adding this ini setting to PHP-7.4 is a no brainer, but I
> >> suggest that we backport it to PHP-7.2 as well.
> >
> > I don't see a reason why not - if the option is useful for improving
> > security/stability, let's backport it. If it's security related, maybe
> > even to 7.1 since it's still in security support (if it's not too hard).
>
> I have applied the PR[1] to PHP-7.2+. Joe may consider to cherry-pick
> to 7.1.
>
> [1] <https://github.com/php/php-src/pull/3709>
>
> --
> Christoph M. Becker
>