RE: [PHP-DEV] bug classification discussion

From: Date: Tue, 01 Nov 2016 17:55:08 +0000
Subject: RE: [PHP-DEV] bug classification discussion
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-96700@lists.php.net to get a copy of this message
Hi Stas, > -----Original Message----- > From: Stanislav Malyshev [mailto:smalyshev@gmail.com] > Sent: Tuesday, November 1, 2016 6:14 PM > To: Nikita Popov <nikita.ppv@gmail.com> > Cc: Anatol Belski <anatol.php@belski.net>; PHP Internals > <internals@lists.php.net>; Remi Collet <remi@fedoraproject.org> > Subject: Re: [PHP-DEV] bug classification discussion > > Hi! > > > I'm also wondering under which category unserialize() issues would > > (usually) fall. I'd assume "low" (because requires documented insecure > > code + well known class of vulnerabilities). > > I'd say medium. While it's documented that unserializing external strings is > unsafe, there is code out there that does exactly that. > Especially older code from times before JSON was mainstream. > I can do that. Regards Anatol

« previous php.internals (#96700) next »