Re: FFI & Security
| From: | Joe Watkins | Date: | Mon, 04 Nov 2019 08:33:00 +0000 |
| Subject: | Re: FFI & Security | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-107760@lists.php.net to get a copy of this message | ||
Morning internals,
Sorry about the delay, this has now been updated.
> There was an unexpected problem communicating with SMTP: Unexpected
return code - Expected: 250, Got: 451 | 451 4.3.0 Error: queue file write
error
Because infrastructure ...
Cheers
Joe
On Wed, 30 Oct 2019 at 12:41, Christoph M. Becker <cmbecker69@gmx.de> wrote:
> On 14.10.2019 at 09:44, Joe Watkins wrote:
>
> > Recently we voted on classification criteria for security bugs [1], we
> > include under "not an issue" any issue that "requires invocation of
> > specific code, which may be valid but is obviously malicious".
> >
> > I would like to add an explicit clause under the "not an issue" section
> for
> > anything related to FFI.
> >
> > It hardly seems worth it to run an RFC, although I'll be happy too if
> there
> > is a single dissenting voice.
> >
> > If there are no objections, I'll modify the document 7 days from today
> > (Monday 21st October).
> >
> > Cheers
> > Joe
> >
> > [1] https://wiki.php.net/security
>
> What is the status here? It seems the security classification document
> has not yet been updated.
>
> Cheers,
> Christoph
>