On Mon, Feb 6, 2012 at 5:22 PM, Reindl Harald <h.rei...@thelounge.net> wrote: > if you anwer to a list mail answer to the list and not private damend! Please, such kind of language is really not necessary. Hitting Reply instead of Reply All happens to everybody once in a while.
> would it have been better to make a full disclosure before > having a fix to help attackers? if this is your opinion > you are a foolsih idiot, sorry but no other words for that Full disclosure sure is controversial, but I don't think it is regarded as necessarily bad. Just look at the way Stefan disclosed the PHP 5.3.9 remote code execution vulnerability: Full disclosure. So please, again, don't call people names. -- PHP Internals - PHP Runtime Development Mailing List To unsubscribe, visit: http://www.php.net/unsub.php