Re: [Fwd: [SA22522] Net_DNS "phpdns_basedir" File Inclusion Vulnerability]

From: Date: Thu, 26 Oct 2006 02:12:34 +0000
Subject: Re: [Fwd: [SA22522] Net_DNS "phpdns_basedir" File Inclusion Vulnerability]
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-44753@lists.php.net to get a copy of this message
Stefan Neufeind, PEAR wrote:
Hi PEARs, though as usual this information is not throughly checked by Secunia, there is some truth behind it. The version-number they wanted to point out is 0.03 and not 0.3, though even a newer version exists. But anyway :-) The vuln they point to actually and still exists. Bug http://pear.php.net/bugs/bug.php?id=9162 was opened for this. Are there any objections to replace $phpdns_basedir with "Net_" completely in the package? (Though this is actually a BC-break!!)
Anyone who uses an alias of "Drago84" should be taken with a grain of salt, but this point aside, your solution sounds good. Please fix this and release a new version. (QA group?) Thanks, Greg

« previous php.pear.dev (#44753) next »