Re: Session: deprecating create_sid() method and add createSid()?

From: Date: Mon, 17 Mar 2014 22:20:48 +0000
Subject: Re: Session: deprecating create_sid() method and add createSid()?
References: 1 2 3 4 5 6 7  Groups: php.internals 
Request: Send a blank email to internals+get-73249@lists.php.net to get a copy of this message
Hi, On Tue, Mar 18, 2014 at 12:07 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > Getting CVE is easy. One just have to describe what the vulnerability is and > send request mail to MITRE. If personnel in MITRE agrees it as new > vulnerability, > then they give us new CVE, if not, they give us existing CVE. > > I don't think this (session_regenerate_id() issue) is PHP's CVE issue as it > may > be avoided by user land like timing attack issue. No, I'm not talking about session_regenerate_id() ... sorry that I mentioned it in this thread. I'd rather not share that publicly until it's resolved, and hence why my question was - can CVEs be hidden until that happens? Cheers, Andrey.

« previous php.internals (#73249) next »