oss-sec mailing list archives
Re: CVE assignment for PHP 5.6.27 and 7.0.12
From: Adam Maris <amaris () redhat com>
Date: Tue, 18 Oct 2016 14:06:41 +0200
On 18/10/16 09:42, Lior Kaplan wrote:
Hi, Please assign a CVE for the following issue: Bug #73147 Use After Free in unserialize() https://bugs.php.net/bug.php?id=73147 http://git.php.net/?p=php-src.git;a=commit;h=0e6fe3a4c96be2d3e88389a5776f878021b4c59f Thanks, Kaplan
16 bugs marked as 'security' were fixed in php 5.6.27 of which only one has CVE assigned. Here you request CVE for another one issue (even the documentation says it's unsafe to use unserialize on untrusted input). Are you planning to obtain CVEs also for other security bugs or do you treat the rest as CVE-unworthy? Or are reporters/community supposed to do it? Thanks! -- Adam Mariš, Red Hat Product Security 1CCD 3446 0529 81E3 86AF 2D4C 4869 76E7 BEF0 6BC2
Current thread:
- CVE assignment for PHP 5.6.27 and 7.0.12 Lior Kaplan (Oct 18)
- Re: CVE assignment for PHP 5.6.27 and 7.0.12 Adam Maris (Oct 18)
- Re: CVE assignment for PHP 5.6.27 and 7.0.12 Lior Kaplan (Oct 18)
- Re: CVE assignment for PHP 5.6.27 and 7.0.12 Remi Collet (Oct 18)
- Re: CVE assignment for PHP 5.6.27 and 7.0.12 Emmanuel Law (Oct 18)
- Re: CVE assignment for PHP 5.6.27 and 7.0.12 cve-assign (Oct 18)
- Re: CVE assignment for PHP 5.6.27 and 7.0.12 Lior Kaplan (Nov 01)
- Re: CVE assignment for PHP 5.6.27 and 7.0.12 cve-assign (Nov 01)
- Re: CVE assignment for PHP 5.6.27 and 7.0.12 Lior Kaplan (Nov 01)
- Re: CVE assignment for PHP 5.6.27 and 7.0.12 Adam Maris (Oct 18)