Re: potential solution to user streams + allow_url_include=off

From: Date: Sat, 19 May 2007 08:00:52 +0000
Subject: Re: potential solution to user streams + allow_url_include=off
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-29540@lists.php.net to get a copy of this message
> If you are aware of some security problems in current PHP sources you > are as always welcome to report them and they will be fixed. I think > everybody here as always are thankful for any help we can get. Ohh BTW. I am aware of many security problems in current PHP, actually the whole world is, because there are still a lot of "local" vulnerabilities unfixed that were disclosed during the MOPB. The ext/filter email issue is also not fixed in 5.2.2 And yes I know a bunch of bugs in PHP that were not disclosed during the MOPB. But what sense does it make to release them now, while a bunch of MOPB bugs are not yet fixed or were marked as fixed in the release notes of 5.2.2 but were not actually fixed. Stefan

« previous php.internals (#29540) next »