Re: [Fwd: [SA22522] Net_DNS "phpdns_basedir" File Inclusion Vulnerability]

From: Date: Thu, 26 Oct 2006 06:13:38 +0000
Subject: Re: [Fwd: [SA22522] Net_DNS "phpdns_basedir" File Inclusion Vulnerability]
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-44758@lists.php.net to get a copy of this message
Greg Beaver wrote: > Stefan Neufeind, PEAR wrote: >> Hi PEARs, >> >> though as usual this information is not throughly checked by Secunia, >> there is some truth behind it. The version-number they wanted to point >> out is 0.03 and not 0.3, though even a newer version exists. But >> anyway :-) >> >> The vuln they point to actually and still exists. Bug >> http://pear.php.net/bugs/bug.php?id=9162 was opened for >> this. >> >> Are there any objections to replace $phpdns_basedir with "Net_" >> completely in the package? (Though this is actually a BC-break!!) > > Anyone who uses an alias of "Drago84" should be taken with a grain of > salt, but this point aside, your solution sounds good. Please fix this > and release a new version. (QA group?) Marko Kaiser already took care of the update, just a minute after opening the bug :-)

« previous php.pear.dev (#44758) next »