RE: [PHP-DEV] bug classification discussion
| From: | Anatol Belski | Date: | Tue, 01 Nov 2016 17:55:08 +0000 |
| Subject: | RE: [PHP-DEV] bug classification discussion | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-96700@lists.php.net to get a copy of this message | ||
Hi Stas,
> -----Original Message-----
> From: Stanislav Malyshev [mailto:smalyshev@gmail.com]
> Sent: Tuesday, November 1, 2016 6:14 PM
> To: Nikita Popov <nikita.ppv@gmail.com>
> Cc: Anatol Belski <anatol.php@belski.net>; PHP Internals
> <internals@lists.php.net>; Remi Collet <remi@fedoraproject.org>
> Subject: Re: [PHP-DEV] bug classification discussion
>
> Hi!
>
> > I'm also wondering under which category unserialize() issues would
> > (usually) fall. I'd assume "low" (because requires documented insecure
> > code + well known class of vulnerabilities).
>
> I'd say medium. While it's documented that unserializing external strings is
> unsafe, there is code out there that does exactly that.
> Especially older code from times before JSON was mainstream.
>
I can do that.
Regards
Anatol