[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sat, 13 Dec 2008 13:54:03 +0100
From: Florian Weimer <fw@...eb.enyo.de>
To: oss-security@...ts.openwall.com
Subject: Re: Re: CVE Request - roundcubemail
* Raphael Geissert:
> I became aware of some sort of code execution vulnerability one day
> before that ticket was reported. After reviewing the file I
> determined that it isn't a vulnerability in roundcube, but in PHP
> itself; but I'm open to be proved wrong.
I think this is a documented feature of preg_replace with the "e"
flag, comparable to what happens when you use string concatenation to
create SQL statements.
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ