Mailing List Archive

[neil.harris@mediachannel.ltd.uk: [Fwd: LWN: A new, remotely exploitable PHP vulnerability]]
----- Forwarded message from Neil Harris <neil.harris@mediachannel.ltd.uk> -----

From: Neil Harris <neil.harris@mediachannel.ltd.uk>
Date: Tue, 23 Jul 2002 09:21:29 +0100
To: Jimmy Wales <jwales@bomis.com>
Subject: [Fwd: LWN: A new, remotely exploitable PHP vulnerability]

Jimbo,

I got delivery failure reports trying to send this to Lee and the
wikitech-l list: perhaps you have a non-Wikipedia E-mail address for Lee?

Regards,

Neil


From: Neil Harris <neil.harris@mediachannel.ltd.uk>
Date: Mon, 22 Jul 2002 23:43:49 +0100
To: lcrocker@nupedia.com, wikitech-l@nupedia.com
Subject: LWN: A new, remotely exploitable PHP vulnerability

This is nasty. The new server is running PHP 4.2.1, which according to
this is potentially vulnerable unless someone installs the patch, or
does the workaround.

Neil

http://lwn.net/Articles/5263/





----- End forwarded message -----
Re: [neil.harris@mediachannel.ltd.uk: [Fwd: LWN: A new, remotely exploitable PHP vulnerability]] [ In reply to ]
> This is nasty. The new server is running PHP 4.2.1, which
> according to this is potentially vulnerable unless someone
> installs the patch, or does the workaround.

On the x86 architecture, this bug will cause PHP to crash
rather than being a security hole, but yes, I will upgrade soon,
probably tonight.

P.S., if you couldn't find my real e-mail address, you weren't
looking very hard. It's on my wiki page, in my signature, and my
home site is the first page returned by Google for my name.
Re: [neil.harris@mediachannel.ltd.uk: [Fwd: LWN: A new, remotely exploitable PHP vulnerability]] [ In reply to ]
> This is nasty. The new server is running PHP 4.2.1, which
> according to this is potentially vulnerable unless someone
> installs the patch, or does the workaround.

On the x86 architecture, this bug will cause PHP to crash
rather than being a security hole, but yes, I will upgrade soon,
probably tonight.

P.S., if you couldn't find my real e-mail address, you weren't
looking very hard. It's on my wiki page, in my signature, and my
home site is the first page returned by Google for my name.