Re: [Fwd: [SA22522] Net_DNS "phpdns_basedir" File Inclusion Vulnerability]
| From: | Stefan Neufeind, PEAR | Date: | Thu, 26 Oct 2006 06:13:38 +0000 |
| Subject: | Re: [Fwd: [SA22522] Net_DNS "phpdns_basedir" File Inclusion Vulnerability] | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-44758@lists.php.net to get a copy of this message | ||
Greg Beaver wrote:
> Stefan Neufeind, PEAR wrote:
>> Hi PEARs,
>>
>> though as usual this information is not throughly checked by Secunia,
>> there is some truth behind it. The version-number they wanted to point
>> out is 0.03 and not 0.3, though even a newer version exists. But
>> anyway :-)
>>
>> The vuln they point to actually and still exists. Bug
>> http://pear.php.net/bugs/bug.php?id=9162 was opened for
>> this.
>>
>> Are there any objections to replace $phpdns_basedir with "Net_"
>> completely in the package? (Though this is actually a BC-break!!)
>
> Anyone who uses an alias of "Drago84" should be taken with a grain of
> salt, but this point aside, your solution sounds good. Please fix this
> and release a new version. (QA group?)
Marko Kaiser already took care of the update, just a minute after
opening the bug :-)