Re: Exploits in PEAR?

From: Date: Wed, 27 Oct 2004 19:19:37 +0000
Subject: Re: Exploits in PEAR?
References: 1 2  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-15169@lists.php.net to get a copy of this message
Ian P. Christian wrote:
On Wednesday 27 October 2004 18:40, Stowe, Nola wrote:
My *network admin* guy is suddenly against PEAR for reasons he does not feel inclined to share with me. I guess reinventing the wheel is more fun (hey, at least its job security, huh?) Does anybody know of any particular exploits or security problems with using PEAR? specifially the DB, DB_DataObject, Services_Weather ???
All publically known issues are probably in the bug database. I am not aware of any such security issues. In case of a security issues people might choose to contact the authors, members of the core qa team or the pear group in order to give prior notice before opening information on possible exploits. However the turn around time for such issues should be in the days, probably hours. We obviously dont know about unknown exploits :-) To conclude we have a pretty good track record and so I doubt that security concerns are a valid reason not to use PEAR. regards, Lukas

« previous php.pear.general (#15169) next »