Re: Re: private bug reports
| From: | Ferenc Kovacs | Date: | Wed, 19 Feb 2014 00:46:24 +0000 |
| Subject: | Re: Re: private bug reports | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72692@lists.php.net to get a copy of this message | ||
On Tue, Feb 18, 2014 at 8:43 PM, Tjerk Meesters <tjerk.meesters@gmail.com>wrote:
> Hi,
>
> I was recently answering a question about null byte injection into PCRE and
> the OP claimed that a pattern such as "~.+~e\x00u" would be accepted; they
> were using 5.3.
>
> The commit that fixed it was this:
>
>
> https://github.com/php/php-src/commit/8b3c1a380a182655113b94b0b96551e98d05a8d3
>
> The corresponding (private) bug is:
> https://bugs.php.net/bug.php?id=55856
>
> My question is whether there's a defined "time out period" after which
> those kind of sensitive bug reports are opened to the public; is it done
> once we hit EOL for that branch?
>
>
> --
> --
> Tjerk
>
AFAIK it should be opened after we have a release with the fix announced,
as there is no point in having a reference to a private bug in the release
announcement/Changelog.
--
Ferenc Kovács
@Tyr43l - http://tyrael.hu