Re: Exploits in PEAR?

From: Date: Wed, 27 Oct 2004 19:23:50 +0000
Subject: Re: Exploits in PEAR?
Groups: php.pear.general 
Request: Send a blank email to pear-general+get-15170@lists.php.net to get a copy of this message
"Stowe, Nola" <NStowe@TheTTGroup.com> wrote: > > My *network admin* guy is suddenly against PEAR for reasons he does not feel > inclined to share with me. I guess reinventing the wheel is more fun (hey, > at least its job security, huh?) A network administrator should not feel particularly opposed to PEAR unless he has to open the firewall for the command to work. However, as the command also runs over a proxy, that should not be an issue. The only thing a network admin should worry about is whether php itself is a security risk. If it isn't (and I think that's a given), he should let the web guys be web guys. > Does anybody know of any particular exploits or security problems with using > PEAR? specifially the DB, DB_DataObject, Services_Weather ??? There is less risk of a security exploit in the PEAR packages going undetected than if you write your own scripts. Most of these scripts do not provide anything nearly as dangerous as register_globals. And it is unlikely given peer-review and the large number of users that an exploit would go unnoticed for long. I remember there was a problem with the Net_Server package when it was in very early stages of development and the release was pulled very quickly. The risk that a package marked stable will have a security exploit is very low. And if it does, it will be fixed in short order. The problems that occur in new releases are generally matters of breaking the api (backwards-compatibility breakage). We have a policy against this, and generally test new releases to ensure that this does not happen. If it does, the release gets pulled quickly. If there is no exploit in the open bugs of a package, you can rest comfortable that it is highly unlikely that one exists - unless you discover it, of course. I do not recall an exploit being reported on a stable release since I joined PEAR the end of 2002. You can search the developer mailing list archives yourself: http://marc.theaimsgroup.com/?l=pear-dev Hope this helps answer your questions, Klaus Guenther QA Core Team

« previous php.pear.general (#15170) next »