Re: [Fwd: [SA22522] Net_DNS "phpdns_basedir" File Inclusion Vulnerability]
| From: | Greg Beaver | Date: | Thu, 26 Oct 2006 02:12:34 +0000 |
| Subject: | Re: [Fwd: [SA22522] Net_DNS "phpdns_basedir" File Inclusion Vulnerability] | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-44753@lists.php.net to get a copy of this message | ||
Stefan Neufeind, PEAR wrote:
Hi PEARs, though as usual this information is not throughly checked by Secunia, there is some truth behind it. The version-number they wanted to point out is 0.03 and not 0.3, though even a newer version exists. But anyway :-) The vuln they point to actually and still exists. Bug http://pear.php.net/bugs/bug.php?id=9162 was opened for this. Are there any objections to replace $phpdns_basedir with "Net_" completely in the package? (Though this is actually a BC-break!!)Anyone who uses an alias of "Drago84" should be taken with a grain of salt, but this point aside, your solution sounds good. Please fix this and release a new version. (QA group?) Thanks, Greg