Re: Session: deprecating create_sid() method and add createSid()?
| From: | Andrey Andreev | Date: | Mon, 17 Mar 2014 22:20:48 +0000 |
| Subject: | Re: Session: deprecating create_sid() method and add createSid()? | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-73249@lists.php.net to get a copy of this message | ||
Hi,
On Tue, Mar 18, 2014 at 12:07 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> Getting CVE is easy. One just have to describe what the vulnerability is and
> send request mail to MITRE. If personnel in MITRE agrees it as new
> vulnerability,
> then they give us new CVE, if not, they give us existing CVE.
>
> I don't think this (session_regenerate_id() issue) is PHP's CVE issue as it
> may
> be avoided by user land like timing attack issue.
No, I'm not talking about session_regenerate_id() ... sorry that I
mentioned it in this thread. I'd rather not share that publicly until
it's resolved, and hence why my question was - can CVEs be hidden
until that happens?
Cheers,
Andrey.