Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:105492 Return-Path: Delivered-To: mailing list internals@lists.php.net Received: (qmail 27103 invoked from network); 29 Apr 2019 06:49:18 -0000 Received: from unknown (HELO mail-pf1-f177.google.com) (209.85.210.177) by pb1.pair.com with SMTP; 29 Apr 2019 06:49:18 -0000 Received: by mail-pf1-f177.google.com with SMTP id e67so4625641pfe.10 for ; Sun, 28 Apr 2019 20:51:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=to:from:subject:openpgp:autocrypt:message-id:date:user-agent :mime-version:content-language:content-transfer-encoding; bh=KrQJmGL/iVjXfPieUrsu3KnxlE9VE8wkXAq39Yo8n/8=; b=A28EDiEndUwL5f9QFnYz4pfvOwtjEoEF0Al5RSs+Vf6PoCJ2WgzGvMpjGUDnbX9vnQ UJz6bE14uu+9aJ3AdfIt1wMH9EGT5HwuPgLT0oDfB23XRtvvfnyhjRC+XF8YFElJFhAZ j5Y2B5QzmCs0ZcqnTTog9YUca7a5sN+3OS4VHv6/m1bpctZrAng9AEL5nPIrl7yzOpAu Juy9htsaQbZg7ziSv0wdZ/uhbl3Z2SL0dFcnIfK7W86liaVjM7nHV9Qg51nMuFhGiR35 VRCT/L7IdJeqBw0N/UwGglGJ8a+J1CHcSEBpabcN2hOS5GuCLsaT7jcJUKkzLKcMz3uj ja0g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:to:from:subject:openpgp:autocrypt:message-id :date:user-agent:mime-version:content-language :content-transfer-encoding; bh=KrQJmGL/iVjXfPieUrsu3KnxlE9VE8wkXAq39Yo8n/8=; b=ifwCLwg0znIHNYss8F5djJTaeEK0UZ7ei+wfUiMrRjdgn2zvBEWpKiwTydHa96tzbb xDMjIqP1f8EiAqb3G1GMIBmCy8hCY+nDP0CclJ6K8cyCC4Fd/mGvDaQrQuh0bkJSKc9C F73UfoL0vH4M6ssb3AvobbYr+DrUdLMXP4qvbMWyn9QrWjcX3oiOkbQUDq9rnEt0p2dE O+8IYTNKOhNiTKIROVQ6DU3ji4G3iPX6Me8YvDIIixhf+F9+Ib05DcPFnveJUffIjRhY sNwoaK0ypWuOs0TYCajnCklEOCjF+sAGfiEf/k9VdfiB/v5PYxebJ8XGP+qKYhYo2BHk EByg== X-Gm-Message-State: APjAAAXmIwIbHECIBFYbRQidFqb+OG5S5ss18XKQXszqPZHCKUfgBt6y hMb21zkkZ6bOYkSaPaPfCg== X-Google-Smtp-Source: APXvYqzQv3bPM600PN2DRMtr2ThYUdsm8Bt8ihJsNeAC/wdTrBk8e/2UOZLuwf9V0HQ5h58Kk822DA== X-Received: by 2002:a62:fb0a:: with SMTP id x10mr26962174pfm.179.1556509865399; Sun, 28 Apr 2019 20:51:05 -0700 (PDT) Received: from Stas-Pro-2016.local (c-24-4-176-254.hsd1.ca.comcast.net. [24.4.176.254]) by smtp.gmail.com with ESMTPSA id x23sm4729034pfo.175.2019.04.28.20.51.04 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 28 Apr 2019 20:51:04 -0700 (PDT) To: PHP Internals , "security@php.net" Openpgp: preference=signencrypt Autocrypt: addr=smalyshev@gmail.com; prefer-encrypt=mutual; keydata= mQMuBE9mqaARCACFSqcGmNunkjQQu3X+yXnTmFeEkvM4JXZTOBdR8aEevNGmmFEfyvjaDjWi 9hcwp4E/lYtC+P7VsVjM1OSX9eq0jC/lGL0ZyRXek+mNy0n5H1NSuTpf9Y18LMqhc4G+RU+L cNiZ9K0DJuOOvNLPxW7OHZguxb3wdKPXNVa2jyRfJAKm2uaJJMT1mTmFT9a0Q8SKr+mUrrJk uG0H2o6SzrKt8Wwoint1eh67zVsJaJtQFchnEZnlawIcqP2yC4nLGR3MkubowxoEBYCZet18 aHVVRbvpG2Qtob8Lu5xrsGbmXymTkHTdpvkfcJFADa8MzOL90zOxXwbGfbIZOlh5En8jAQCX lfnx2eQL3BSW/6XANa51dbWiEp1d1BAkpGKtZvlk0Qf+M9WAi+9aXMe3xP5krxtgnRNUf2WN 6Zdy2MxL1RRJCFbytLhl0ronC49BsGYVGshdEH8xhBbiIOJKuVZ/DTl9bEm7P9c7CC7iJyVC khUAhouH6xzZQNLR+RU+QebYzXypVfl99Qk7EdMmr/WAZCHLuvanyqepC5EBsa3VnAfQemSN oBeGBKWWLiOsPjvS72+y1z4RUMAfXHn4l/sFMt8zt7/74AmJPwZquV41p4mPO12V4+xPyc6R sB84sfsk2QVivU8w8AkvGQeYjXoz7Iwao95+fWteVzZ36KRQvUckP8pGjHlDXnHxJ0HI1I/k OBZSjwRwUf0dd73y6erPhbLk+gf+NdI3H9KGJBzG5/rVyWKwUeQ9d5ud4jTJRkQGvAP5pg76 vEa9dogbpe4W5Z+0BfbiJSnQmQWSHiZddj/t33ptbup44Ck6ZTgdlmFYMLF1hR47PIZTDKER EuKYGci/vq8snZvEJP9YCw/TtiHcMdrMKcY/+Lp8lQO0GHLPB9glVhnC0db6l1Xpg1CMI8/R ozBMcij30EgATggC/y2zbiqAFoS9FN9nXPbe4phStqABEyeZ+nXudt7PUYTjVgcrqo8bHZCi sBobWC7OnKyUzxVxzUeuPkIfmZuzkLaMw2McQdvwwsNvQ0DzaLP30c1Xsm/7EIYJcOWpzlVJ 5QrdmE0/BbQyU3RhbmlzbGF2IE1hbHlzaGV2IChQSFAga2V5KSA8c21hbHlzaGV2QGdtYWls LmNvbT6IegQTEQgAIgUCT2aqtAIbAwYLCQgHAwIGFQgCCQoLBBYCAwECHgECF4AACgkQL3lW vF2gS12XMwD9HuRIolSwIK77u8EY461y2u6sbX36n5/uo/LDQuxoi3sA/0MvpnvzOhv9Iufv vsZEj3E7i3h+iD5648YMwfTFCij+uQINBE9mqaAQCADfZPMpjZkkGZj3BY/7ApoLq4mwqzbh +CpLXwNn20tFNvSXfb8RdeXvVEb7Scx+W9qYpiaun2iXJgCVH8fgpZpR856ulT1q6uCG++CX ubEvip/eJkZl93/84h04KQJwsgOrAh0Om3OePRn8Pr+++0LNS0EL8uX/YHeTOGOnnmTqYTey SBVFdov6L4mepddfjekicKQqhL7mZh/xuq29JijT0uNNX8v4vDWQDu5dlAcdd+uB3gcXMD/P ginD11zp+6wtrWCm/+yBqpvDwXQX5PGUnwvbRfl7Ay3MmwmoXiecZMg0dwTSc7e0lhB4HGRH ZdBMJB4rHUVGdzqujK/ctOvrAAMFB/0Utb76Qe6sCMlHxVAmeE/fbo7Pi05btZ/x01r67dHf aMSP0riCKJ7M0OW+jAXtu9+z/BVnYisW67WWfxl2cS5tZDgiHgJARXWUOO72+sScHP8KQmTl 1z16gyKbwY3SmyBkwcpOL35nhUWNLy93syPoY6sZUTikr2bZYukHDQ33XBPs4e6MbWKfsa9q aVmnlOF3k5UqChjutfHaEa4Q7VP4wBIpphHBi9MI16oJIzzBPbGl2uoedjwiZ6QeQZnSuOVY ZxU2d3lRA8PrtfFN1VSlpEm/VcAvtieHUYWHN0wOu+cp3Slr5XJVNjTjJhl28SlinMME54mK AGf2Ldr/dRwXiGEEGBEIAAkFAk9mqaACGwwACgkQL3lWvF2gS126EQD/VVd3FgjLKglClRQP zdfU847tqDK4zJjbmRv5vLLwoE0A+wbrQs7jVGU3NrS0AIl5vUmewpp2BKzSkepy23nWmejw Message-ID: Date: Sun, 28 Apr 2019 20:51:03 -0700 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:60.0) Gecko/20100101 Thunderbird/60.6.1 MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit Subject: Issuing CVEs for PHP From: smalyshev@gmail.com (Stanislav Malyshev) Hi! I have set up PHP as CNA (CVE Identifiers authority) with MITRE. That means that we will be assigning our own CVEs from now on. The process in broad strokes works like this: 1. We request a block of numbers 2. When we have security bug, we use one of the numbers in the block 3. We create CVE descriptions and commit them to the cvelist repo Much more detailed documentation on how it is done is here: https://wiki.php.net/cve So far I am the only one who is registered to commit CVE descriptions to MITRE upstream repo, but if somebody wants to do it too, I'm sure it can be arranged. Note that you can assign CVE to a bug not yet fixed or published in the open. Please use this capability responsibly and keep the tracking in https://wiki.php.net/cve . If you are not familiar with the process or don't want to bother, just put "needed" as CVE number and it will be taken care of. Please not enter the bug details into the public repo before the fix is released. If you have any questions about this, please ask me. -- Stas Malyshev smalyshev@gmail.com