Re: [VOTE] Improve unserialize() error handling
| From: | Dan Ackroyd | Date: | Thu, 20 Oct 2022 13:40:59 +0000 |
| Subject: | Re: [VOTE] Improve unserialize() error handling | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-118858@lists.php.net to get a copy of this message | ||
On Wed, 19 Oct 2022 at 19:11, Tim Düsterhus <tim@bastelstu.be> wrote:
>
> While the behavior would in fact change, it would not introduce a
> "security issue" if this what you were hinting at.
No, just that it would break in production, and then have to be fixed
after a live site was already affecting end-users.
> This would just result in an uncaught Exception which should
> be very visible in your error tracking service.
My impression is that most web-servers running PHP don't have those.
For people who run most sites, the first they would know about it is
when end-users started complaining.
cheers
Dan
Ack