Bug#361853: not fixed in etch

2006-08-16 Thread Stefan Fritsch
severity 361853 important
thanks

On Tuesday 15 August 2006 11:14, Thijs Kinkhorst wrote:
 However, phpinfo() is a debug tool. I don't know why you would want
 to use it on a production system and inside a context where cookies
 contain security relevant information at the same time. If you ask
 me, this is 'important' at most. Secunia labels it as not
 critical.

You are right. For some reason, I thought is was already marked 
important by Steve's mail.

Cheers,
Stefan


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#361853: not fixed in etch

2006-08-15 Thread Thijs Kinkhorst
Hello Stefan,

 according to secunia [1], this has been fixed in 4.4.3, not in 4.4.2
 
 [1] http://secunia.com/advisories/19599

I've verified that the bug is indeed marked as fixed in the 4.4.3
changelog of PHP.

However, phpinfo() is a debug tool. I don't know why you would want to
use it on a production system and inside a context where cookies contain
security relevant information at the same time. If you ask me, this is
'important' at most. Secunia labels it as not critical.


Thijs


signature.asc
Description: This is a digitally signed message part


Bug#361853: not fixed in etch

2006-08-14 Thread Stefan Fritsch
found 361853 4:4.4.2-1.1
thanks

according to secunia [1], this has been fixed in 4.4.3, not in 4.4.2

[1] http://secunia.com/advisories/19599


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]