Re: PHP Update .. details

2004-12-25 Thread Harry Sufehmi
Initially a few CVE numbers were assigned and then later withdrawn when it became clear that the issues could only be exploited by a user who wrote a malicious PHP script - not a remote issue, or too serious. (Given that if you had the ability to write evil PHP code you cold just run 'system('rm

Re: PHP Update .. details

2004-12-23 Thread Hans Kratz
Hi! > It's looking like there won't be an update to PHP for Woody, because > the majority of the PHP issues aren't relevent. > > Initially a few CVE numbers were assigned and then later withdrawn > when it became clear that the issues could only be exploited by a > user who wrote a malicio

PHP Update .. details

2004-12-23 Thread Steve Kemp
It's looking like there won't be an update to PHP for Woody, because the majority of the PHP issues aren't relevent. Initially a few CVE numbers were assigned and then later withdrawn when it became clear that the issues could only be exploited by a user who wrote a malicious PHP script -