Re: is_a fix for 5.4 and HEAD
| From: | Pierre Joye | Date: | Sun, 16 Oct 2011 23:56:02 +0000 |
| Subject: | Re: is_a fix for 5.4 and HEAD | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-55828@lists.php.net to get a copy of this message | ||
On Mon, Oct 17, 2011 at 12:59 AM, Stas Malyshev <smalyshev@sugarcrm.com> wrote:
> Yes, the security problem was present before the fix was applied
No, it was not. See the examples in the links I pasted earlier.
The code was safe, under controlled context, before this change has
applied. With the change the code becomes unsafe under uncontrolled
context. That's not acceptable and besides the BC break, it introduce
a security flaw. As stated many times, by many persons, in the
previous discussion(s).
Cheers,
--
Pierre
@pierrejoye | http://blog.thepimp.net | http://www.libgd.org