oss-sec mailing list archives

Re: CVE request (PHP 5.3.x getSymbol() DoS; CERT VU#479900)


From: Tomas Hoger <thoger () redhat com>
Date: Thu, 9 Dec 2010 13:00:43 +0100

Hi Pierre!

On Wed, 8 Dec 2010 08:56:02 +0100 Pierre Joye wrote:

The CVE # has been added to the changes log too.

http://svn.php.net/viewvc?view=revision&revision=306036

Were you following the rest of the discussion in this thread?  Should I
file upstream bug for NumberFormatter::setSymbol issue so it can be
fixed before 5.3.4 too?

-- 
Tomas Hoger / Red Hat Security Response Team


Current thread: