Re: Re: private bug reports

From: Date: Thu, 20 Feb 2014 01:40:29 +0000
Subject: Re: Re: private bug reports
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-72696@lists.php.net to get a copy of this message
On Wed, Feb 19, 2014 at 8:46 AM, Ferenc Kovacs <tyra3l@gmail.com> wrote: > > > > On Tue, Feb 18, 2014 at 8:43 PM, Tjerk Meesters <tjerk.meesters@gmail.com>wrote: > >> Hi, >> >> I was recently answering a question about null byte injection into PCRE >> and >> the OP claimed that a pattern such as "~.+~e\x00u" would be accepted; they >> were using 5.3. >> >> The commit that fixed it was this: >> >> >> https://github.com/php/php-src/commit/8b3c1a380a182655113b94b0b96551e98d05a8d3 >> >> The corresponding (private) bug is: >> https://bugs.php.net/bug.php?id=55856 >> >> My question is whether there's a defined "time out period" after which >> those kind of sensitive bug reports are opened to the public; is it done >> once we hit EOL for that branch? >> >> >> -- >> -- >> Tjerk >> > > AFAIK it should be opened after we have a release with the fix announced, > as there is no point in having a reference to a private bug in the release > announcement/Changelog. > Thanks. If that's indeed the case, could someone please open the bug report? :) > > -- > Ferenc Kovács > @Tyr43l - http://tyrael.hu > -- -- Tjerk

« previous php.internals (#72696) next »