Re: Exploits in PEAR?
| From: | Lukas Smith | Date: | Wed, 27 Oct 2004 19:19:37 +0000 |
| Subject: | Re: Exploits in PEAR? | ||
| References: | 1 2 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-15169@lists.php.net to get a copy of this message | ||
Ian P. Christian wrote:
On Wednesday 27 October 2004 18:40, Stowe, Nola wrote:All publically known issues are probably in the bug database. I am not aware of any such security issues. In case of a security issues people might choose to contact the authors, members of the core qa team or the pear group in order to give prior notice before opening information on possible exploits. However the turn around time for such issues should be in the days, probably hours. We obviously dont know about unknown exploits :-) To conclude we have a pretty good track record and so I doubt that security concerns are a valid reason not to use PEAR. regards, LukasMy *network admin* guy is suddenly against PEAR for reasons he does not feel inclined to share with me. I guess reinventing the wheel is more fun (hey, at least its job security, huh?) Does anybody know of any particular exploits or security problems with using PEAR? specifially the DB, DB_DataObject, Services_Weather ???