Re: bug classification discussion
| From: | Yasuo Ohgaki | Date: | Tue, 01 Nov 2016 20:44:06 +0000 |
| Subject: | Re: bug classification discussion | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-96701@lists.php.net to get a copy of this message | ||
Hi Stas,
On Sun, Oct 30, 2016 at 2:21 PM, Stanislav Malyshev <smalyshev@gmail.com> wrote:
> So I wrote a first version of the document Anatol mentioned:
>
> https://wiki.php.net/security
>
> Please comment. Fixes to the grammar and typos are especially welcome
> (you can just do them in the wiki without asking :)
Nice work!
Reasonable content.
It may better to include Q&A for open_basedir that bypassing
open_basedir restrictions via module features are not considered as
security bugs. open_basedir restriction is to mitigate impact on
unwanted PHP code execution, not a complete solution.
We have "security bug" in document also. It may be better to mention
them and encourage users to report this kind of bug also.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net