BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: [Full-disclosure] Critical PHP bug - act ASAP if you are runningweb with sensitive data Mar 28 2006 08:45PM
Tõnu Samuel (tonu jes ee)
Stefan Esser wrote:

>The bug is a binary safety issue in html_entity_decode. A function that
>is not usually used on user input, because user input is usually not
>expected in HTML format and then decoded. Even if the function is used
>on user input it can only leak memory to a potential attacker i...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus