Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:67642 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 44256 invoked from network); 7 Jun 2013 12:05:37 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 7 Jun 2013 12:05:37 -0000 Authentication-Results: pb1.pair.com smtp.mail=tyra3l@gmail.com; spf=pass; sender-id=pass Authentication-Results: pb1.pair.com header.from=tyra3l@gmail.com; sender-id=pass Received-SPF: pass (pb1.pair.com: domain gmail.com designates 209.85.223.182 as permitted sender) X-PHP-List-Original-Sender: tyra3l@gmail.com X-Host-Fingerprint: 209.85.223.182 mail-ie0-f182.google.com Received: from [209.85.223.182] ([209.85.223.182:33985] helo=mail-ie0-f182.google.com) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id 0A/C1-33815-E8CC1B15 for ; Fri, 07 Jun 2013 08:05:35 -0400 Received: by mail-ie0-f182.google.com with SMTP id 9so10259089iec.41 for ; Fri, 07 Jun 2013 05:05:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=Qdt1qyTaj36v/ThHddxDJ08VbsCSZ+/Wuks5Y7RVazY=; b=sl9jbArsnjC75t/Pv/++8RSx+0sK6fI/KLeuiU66k8cqcl1JgWcpMqLN/Px83GXwz+ 8pH/y2cG6dy8TwFJmTXtV+5lyNRGyPAyHktIaFbJ+48J1lIB/27X2aUMyonm8dmNioWA vnvxd8z8Rlq8SJrRW5eHwvCZlhtnqkWV9x+Kvj3g/BW6152h99zSw6eBb0Erp17Y3DPG DLxO5gmeP4ZJdpdLrWUwzT4Z+5rDlpSwD5AeB72DRi/HBiDvQixgDSldRNHYF+CElmfj VjeoaUnRz9IKdx4fvNXS0hNf4l5Fof3S8H8Fcsmho2F31BpLVXGBaru3QEWyxfPjUdXb p7pg== MIME-Version: 1.0 X-Received: by 10.50.88.40 with SMTP id bd8mr752125igb.37.1370606732115; Fri, 07 Jun 2013 05:05:32 -0700 (PDT) Received: by 10.50.65.8 with HTTP; Fri, 7 Jun 2013 05:05:31 -0700 (PDT) In-Reply-To: References: Date: Fri, 7 Jun 2013 14:05:31 +0200 Message-ID: To: Pierre Schmitz Cc: PHP Internals Content-Type: multipart/alternative; boundary=089e0122a04c650a4504de8f3fd2 Subject: Re: [PHP-DEV] PHP 5.4.16 and PHP 5.3.26 released! From: tyra3l@gmail.com (Ferenc Kovacs) --089e0122a04c650a4504de8f3fd2 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On Fri, Jun 7, 2013 at 6:34 AM, Pierre Schmitz wrote: > Am 07.06.2013 01:58, schrieb Stas Malyshev: > > Hello! > > > > The PHP development team announces the immediate availability of PHP > > 5.4.16 and PHP 5.3.26. These releases fix about 15 bugs, including > > CVE-2013-2110. All users of PHP are encouraged to upgrade to PHP 5.4.16= . > > PHP 5.3.26 is recommended for those wishing to remain on the 5.3 series= . > > Is there a way to access the content of the relevant bug report here? > https://bugs.php.net/bug.php?id=3D64879 Who is allowed to see these > private reports? > > private bugs can be only accessed by the php security team and some security people from vendors: http://git.php.net/?p=3Dweb/bugs.git;a=3Dblob;f=3Dinclude/trusted-devs.php I think that private bugs like that should be made public after the fixed version release, just like others do the same: https://bugzilla.redhat.com/show_bug.cgi?id=3D964969 usually searching for a CVE number on google works (after the fix is released). --=20 Ferenc Kov=C3=A1cs @Tyr43l - http://tyrael.hu --089e0122a04c650a4504de8f3fd2--