Re: [PHP-DEV] Want to know about security vulnerablity that was fixed in PHP4.3.8

2004-07-20 Thread Stefan Esser
Hello, 1)Only code that tries to create/initialize a Non-Persistent hash table is vulnerable under certain cases. True or False. False, anything that is not correctly initialised at the time the memory_limit request termination kicks in can potentially be exploited. This includes string pointers.

[PHP-DEV] Want to know about security vulnerablity that was fixed in PHP4.3.8

2004-07-20 Thread Kamesh Jayachandran
Hi All, I have PHP-4.2.3. As per http://security.e-matters.de/advisories/112004.html , my PHP is vulnerable. I have a overview of the problem. Can someone answer my questions which make my understanding of the problem even better? 1)Only code that tries to create/initialize a Non-Persistent hash ta