Re: bug classification discussion

From: Date: Tue, 01 Nov 2016 17:13:42 +0000
Subject: Re: bug classification discussion
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-96698@lists.php.net to get a copy of this message
Hi! > I'm also wondering under which category unserialize() issues would > (usually) fall. I'd assume "low" (because requires documented insecure > code + well known class of vulnerabilities). I'd say medium. While it's documented that unserializing external strings is unsafe, there is code out there that does exactly that. Especially older code from times before JSON was mainstream. -- Stas Malyshev smalyshev@gmail.com

« previous php.internals (#96698) next »