Re: bug classification discussion

From: Date: Tue, 01 Nov 2016 09:32:10 +0000
Subject: Re: bug classification discussion
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-96693@lists.php.net to get a copy of this message
On Sun, Oct 30, 2016 at 6:21 AM, Stanislav Malyshev <smalyshev@gmail.com> wrote: > Hi! > > So I wrote a first version of the document Anatol mentioned: > > https://wiki.php.net/security > > Please comment. Fixes to the grammar and typos are especially welcome > (you can just do them in the wiki without asking :) > It would be nice to add specific examples (e.g. the string overflow case to low). I'm also wondering under which category unserialize() issues would (usually) fall. I'd assume "low" (because requires documented insecure code + well known class of vulnerabilities). Nikita

« previous php.internals (#96693) next »