Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:104659 Return-Path: Delivered-To: mailing list internals@lists.php.net Received: (qmail 83998 invoked from network); 11 Mar 2019 19:45:44 -0000 Received: from unknown (HELO mout.gmx.net) (212.227.17.22) by pb1.pair.com with SMTP; 11 Mar 2019 19:45:44 -0000 Received: from [192.168.2.104] ([79.222.45.201]) by mail.gmx.com (mrgmx101 [212.227.17.168]) with ESMTPSA (Nemesis) id 0M3eDF-1glzdS0tG5-00rLDQ; Mon, 11 Mar 2019 17:35:23 +0100 To: Stanislav Malyshev , PHP internals References: <46354329-38ca-82a2-352d-71394e0ce6bd@gmx.de> Cc: Joe Watkins Message-ID: Date: Mon, 11 Mar 2019 17:35:23 +0100 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.5.3 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8 Content-Language: de-DE Content-Transfer-Encoding: 7bit X-Provags-ID: V03:K1:py/yEnPvB4ecwjPREQ8kOd6r843ZAP/lXOyAsiF/Tg6FNEN2WZw Z2x9PeHg/TNxCv8xfsIgDoj+evDYVDn8cGdr1cIKUmxHbz2kaNPq6vYVDnXXxsL6714q22o G3S0pO5t/45wqiFGInEEOvFz3N7EE1AUeSk9z8tgxA+e48VecThvBEZBmeddZ0q44jdqmAW 72GG2xrutCxAut3oXE7/w== X-Spam-Flag: NO X-UI-Out-Filterresults: notjunk:1;V03:K0:cMNv87lV034=:UE1iNpagMdgLPjskUqzrAW iq5MqSZV6Eivlh9RX4//wSiR+sawmr63skIAmvw0npYIlC9i4YOGj16QfZnYSKrg4D1GFb7ci fByDD+0kkn1aSCzkZYBn1vTCP168nH/n8XyZ0aJnjANih/avpIHJecTvDt4LntWEJuTDUD3hA WAdJnBX6HMDgo1qa9fAAvTF7q8jNguAdG4Cwqn6cYL5lSo85K/Xk0TYgXn3Eu3P1tr5X56VMK IrSd3pO679ndJvvlymKh0Vw54OJFgYInHuIFMCygL7PS3CV966+eFrEKedM5FToup1QX/Ns9Z WAVeITCIyY/22/mc6sidzcxtKThBAU3GgHljcqAxyogfLWKVGwraHH7Sbfrz2h2IRBt1IDOG7 anvsV6GlVPo8Qu/gbttPcFJYxpF6oPYERSgv509IzlEOr71S78OOPxX3VBxeZ4GuVEt4bSvdJ emx2Cq5AzU4akrfkMhl/j7uFkIRyFIN3sCU+5BVmT25XD8p9j+Zq6TRsFNinZywTZ3llUVkXQ mCTQS0/0XTXEObXLMDuvIxgskWE2oElGSgNC5wSCdkCnaPC5yYrtGaBOIEhkJqUkffwdrnEpq dOw3rKn12FXYUQyOcL6bNm8XeCd1E4NKVN7Rf/wi5mCNwEGG3IsB3ORO7fQOyBycc1EnByuRd k19TimOxbOTl70MQhFLXBS1BhSFMKz22yGKGa8bFa9E0gZremi7w3U9yxnoK0F/gre0pG7ua5 yzCJhlYOoMzZbjjn0jO0wvpBT+erlVu7wpmPWhFOD0qQdkuGWbnbIMlcXY53PfGLKrYiyQuyV MJzOmf1ZQaQhslcDcogsoI3e6xpr73PzfHzL3tzhcr0CdN/YPmnv72kWhXvxhoIx40dE7kOPN L8mlVUj1KpyRTqON6HRVTMlKQCIERXJ+B/ripDVUolpoPLS07K7dSjYiZkO8P7+oH8pokRaKz 8E/wltaNHVA== Subject: =?UTF-8?Q?Re=3a_=5bPHP-DEV=5d_Mitigate_=e2=80=9cMagellan_vulnerabil?= =?UTF-8?B?aXRpdGVz4oCdIGluIFBIUCA3LjI/?= From: cmbecker69@gmx.de ("Christoph M. Becker") On 19.02.2019 at 02:16, Stanislav Malyshev wrote: >> In my opinion, adding this ini setting to PHP-7.4 is a no brainer, but I >> suggest that we backport it to PHP-7.2 as well. > > I don't see a reason why not - if the option is useful for improving > security/stability, let's backport it. If it's security related, maybe > even to 7.1 since it's still in security support (if it's not too hard). I have applied the PR[1] to PHP-7.2+. Joe may consider to cherry-pick to 7.1. [1] -- Christoph M. Becker