Re: bug classification discussion
| From: | Stanislav Malyshev | Date: | Tue, 01 Nov 2016 17:13:42 +0000 |
| Subject: | Re: bug classification discussion | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-96698@lists.php.net to get a copy of this message | ||
Hi!
> I'm also wondering under which category unserialize() issues would
> (usually) fall. I'd assume "low" (because requires documented insecure
> code + well known class of vulnerabilities).
I'd say medium. While it's documented that unserializing external
strings is unsafe, there is code out there that does exactly that.
Especially older code from times before JSON was mainstream.
--
Stas Malyshev
smalyshev@gmail.com