#25753 [Com]: php_value|flag / php_admin_* settings "leak" from vhosts/.htaccess files

2004-01-28 Thread rover at tob dot ru
ID: 25753 Comment by: rover at tob dot ru Reported By: [EMAIL PROTECTED] Status: Closed Bug Type: Apache related Operating System: * PHP Version: 4CVS, 5CVS New Comment: Anyway - in some case this can lead to security violation. Apache2

#25753 [Com]: php_value|flag / php_admin_* settings "leak" from vhosts/.htaccess files

2004-01-27 Thread rover at tob dot ru
ID: 25753 Comment by: rover at tob dot ru Reported By: [EMAIL PROTECTED] Status: Critical Bug Type: Apache related Operating System: * PHP Version: 4CVS, 5CVS New Comment: We examine source files more carefull and remake a patch: diff -udr

#25753 [Com]: php_value|flag / php_admin_* settings "leak" from vhosts/.htaccess files

2004-01-27 Thread rover at tob dot ru
ID: 25753 Comment by: rover at tob dot ru Reported By: [EMAIL PROTECTED] Status: Critical Bug Type: Apache related Operating System: * PHP Version: 4CVS, 5CVS New Comment: 2 hour later We analyze this bug more carefully. THIS BUG VERY

#25753 [Com]: php_value|flag / php_admin_* settings "leak" from vhosts/.htaccess files

2004-01-27 Thread rover at tob dot ru
ID: 25753 Comment by: rover at tob dot ru Reported By: [EMAIL PROTECTED] Status: Critical Bug Type: Apache related Operating System: * PHP Version: 4CVS, 5CVS New Comment: Latest patch have a disadvantage: seems options like 'php_

#25753 [Com]: php_value|flag / php_admin_* settings "leak" from vhosts/.htaccess files

2004-01-27 Thread rover at tob dot ru
ID: 25753 Comment by: rover at tob dot ru Reported By: [EMAIL PROTECTED] Status: Critical Bug Type: Apache related Operating System: * PHP Version: 4CVS, 5CVS New Comment: You can try this patch: (applied to 4.3.3, 4.3.4 and 4.3.5RC1

#25753 [Com]: php_value|flag / php_admin_* settings "leak" from vhosts/.htaccess files

2004-01-27 Thread rover at tob dot ru
ID: 25753 Comment by: rover at tob dot ru Reported By: [EMAIL PROTECTED] Status: Critical Bug Type: Apache related Operating System: * PHP Version: 4CVS, 5CVS New Comment: It seems we have found a bug in mod_php4.c. We can 100% reproduce