Re: potential solution to user streams + allow_url_include=off

From: Date: Sat, 19 May 2007 08:20:46 +0000
Subject: Re: potential solution to user streams + allow_url_include=off
References: 1 2 3 4 5 6  Groups: php.internals 
Request: Send a blank email to internals+get-29542@lists.php.net to get a copy of this message
Ohh BTW. I am aware of many security problems in current PHP, actually the whole world is, because there are still a lot of "local" vulnerabilities unfixed
We seem to be in a disagreement about what security vulnerability is. However, it is not very important since bugs are to be fixed anyway. I am aware of one issue still unfixed - listed as #27 and #28. There are also #1 and #2 which can not be fixed right now. Are there any other?
that were disclosed during the MOPB. The ext/filter email issue is also not fixed in 5.2.2
I was talking about current code. Barring the possibility of time travel, there's no way to fix anything in 5.2.2 now, so discussing it is kinda pointless.
And yes I know a bunch of bugs in PHP that were not disclosed during the MOPB.
And you do not report them because?
But what sense does it make to release them now, while a bunch of MOPB bugs are not yet fixed or were marked as fixed in the release notes of 5.2.2 but were not actually fixed.
Those being? -- Stanislav Malyshev, Zend Products Engineer stas@zend.com http://www.zend.com/

« previous php.internals (#29542) next »