Bug#336645: PHP 4.4.1 fixes security bugs

2005-11-01 Thread Florian Weimer
* Steve Langasek: > However, in reading over the description of the vulnerabilities, I don't > really see any grounds for regarding these as grave securty bugs. The most > severe of these problems, 202005.79, only has a significant impact when > register_globals is set in the PHP environment -- a

Bug#336645: PHP 4.4.1 fixes security bugs

2005-10-31 Thread Steve Langasek
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Mon, Oct 31, 2005 at 07:14:55PM +0100, Florian Weimer wrote: > Package: php4 > Tags: security > Severity: grave > The Hardened-PHP project has disclosed several security > vulnerabilites: > >

Bug#336645: PHP 4.4.1 fixes security bugs

2005-10-31 Thread Florian Weimer
* Florian Weimer: > This appears to be a variant of CVE-2002-1954, although public information is scarce at this stage. See the discussion on full-disclosure and various other places. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a

Bug#336645: PHP 4.4.1 fixes security bugs

2005-10-31 Thread Florian Weimer
Package: php4 Tags: security Severity: grave The Hardened-PHP project has disclosed several security vulnerabilites: