Re: Exploits in PEAR?
| From: | Klaus Guenther | Date: | Wed, 27 Oct 2004 19:23:50 +0000 |
| Subject: | Re: Exploits in PEAR? | ||
| Groups: | php.pear.general | ||
| Request: | Send a blank email to pear-general+get-15170@lists.php.net to get a copy of this message | ||
"Stowe, Nola" <NStowe@TheTTGroup.com> wrote:
>
> My *network admin* guy is suddenly against PEAR for reasons he does not
feel
> inclined to share with me. I guess reinventing the wheel is more fun
(hey,
> at least its job security, huh?)
A network administrator should not feel particularly opposed to PEAR unless
he has to open the firewall for the command to work. However, as the command
also runs over a proxy, that should not be an issue. The only thing a network
admin should worry about is whether php itself is a security risk. If it
isn't (and I think that's a given), he should let the web guys be web guys.
> Does anybody know of any particular exploits or security problems with
using
> PEAR? specifially the DB, DB_DataObject, Services_Weather ???
There is less risk of a security exploit in the PEAR packages going
undetected than if you write your own scripts. Most of these scripts do not
provide anything nearly as dangerous as register_globals. And it is unlikely
given peer-review and the large number of users that an exploit would go
unnoticed for long. I remember there was a problem with the Net_Server
package when it was in very early stages of development and the release was
pulled very quickly.
The risk that a package marked stable will have a security exploit is very
low. And if it does, it will be fixed in short order. The problems that occur
in new releases are generally matters of breaking the api
(backwards-compatibility breakage). We have a policy against this, and
generally test new releases to ensure that this does not happen. If it does,
the release gets pulled quickly.
If there is no exploit in the open bugs of a package, you can rest
comfortable that it is highly unlikely that one exists - unless you discover
it, of course. I do not recall an exploit being reported on a stable release
since I joined PEAR the end of 2002. You can search the developer mailing
list archives yourself:
http://marc.theaimsgroup.com/?l=pear-dev
Hope this helps answer your questions,
Klaus Guenther
QA Core Team