Re: bug classification discussion

From: Date: Tue, 01 Nov 2016 20:44:06 +0000
Subject: Re: bug classification discussion
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-96701@lists.php.net to get a copy of this message
Hi Stas, On Sun, Oct 30, 2016 at 2:21 PM, Stanislav Malyshev <smalyshev@gmail.com> wrote: > So I wrote a first version of the document Anatol mentioned: > > https://wiki.php.net/security > > Please comment. Fixes to the grammar and typos are especially welcome > (you can just do them in the wiki without asking :) Nice work! Reasonable content. It may better to include Q&A for open_basedir that bypassing open_basedir restrictions via module features are not considered as security bugs. open_basedir restriction is to mitigate impact on unwanted PHP code execution, not a complete solution. We have "security bug" in document also. It may be better to mention them and encourage users to report this kind of bug also. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#96701) next »