Archive for March 6th, 2007

Month of PHP bugs and extensions.ini “magic” order madness

Just came across this while tracking the cause of frequent apache crashes on one of the development boxes running on FreeBSD. Default installation of PHP from FreeBSD’s ports includes Suhosin patch which aims to harden PHP. Well, it’s good to have good people looking after the security of PHP.

The Month of PHP Bugs

“formerly known as March”

"This initiative is an effort to improve the security of PHP. However we will not concentrate on problems in the PHP language that might result in insecure PHP applications, but on security vulnerabilities in the PHP core. During March 2007 old and new security vulnerabilities in the Zend Engine, the PHP core and the PHP extensions will be disclosed on a day by day basis. We will also point out necessary changes in the current vulnerability managment process used by the PHP Security Response Team." - Month of PHP bugs.

(more…)

Tuesday, March 6th, 2007