Gentoo Archives: gentoo-server

From: Luca Longinotti <chtekk@g.o>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] gentoo php 5.1.6-pl6 htmlentities() double free
Date: Sun, 11 Feb 2007 16:32:12
Message-Id: 45CF4453.8000103@gentoo.org
In Reply to: [gentoo-server] gentoo php 5.1.6-pl6 htmlentities() double free by ascii
1 ascii wrote:
2 > During "software development" with Di Paola we found that latest php5
3 > stable version available for gentoo (5.1.6) is affected by a double
4 > free in the htmlentities() function, commonly exposed to user input.
5 > ...
6
7 We already know of this, please search https://bugs.gentoo.org/ when
8 reporting such stuff, you'd have noticed
9 https://bugs.gentoo.org/show_bug.cgi?id=153911 already. I know we're
10 terribly late on this one, but a combination of things is holding this
11 up until I can get 5.2.1 in the tree, which should be in a few days, and
12 that will fix this and many other problems.
13
14 --
15 Best regards,
16 Luca Longinotti aka CHTEKK
17
18 LongiTEKK Networks Admin: chtekk@×××××××××.com
19 Gentoo Dev: chtekk@g.o
20 SysCP Dev: chtekk@×××××.org
21 TILUG Supporter: chtekk@×××××.ch

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-server] gentoo php 5.1.6-pl6 htmlentities() double free ascii <ascii@××××××××.com>