Mombu the Php Forum sponsored links

Go Back   Mombu the Php Forum > Php > Anyone against requiring libxml2 2.6.x for PHP5.1?
User Name
Password
REGISTER NOW! Mark Forums Read

sponsored links


Reply
 
1 11th March 10:48
rasmus
External User
 
Posts: 1
Default Anyone against requiring libxml2 2.6.x for PHP5.1?



Given the way XML is used in xmlrpc and SOAP systems, I don't think I
would classify a security problem in libxml as a local exploit. Much
more so than any other library, libxml2 is going to be reading remote
xml data and acting on the contents so chances are any security problem
in it is going to lead to a remote exploit. For example, a recent one:

http://seclists.org/lists/fulldisclosure/2004/Nov/0084.html

With an exploit here:

http://www.k-otik.com/exploits/20041026.libxml2.c.php

-Rasmus

--
PHP Internals - PHP Runtime Development Mailing List
To unsubscribe, visit: http://www.php.net/unsub.php
  Reply With Quote


  sponsored links


Reply


Thread Tools
Display Modes




Copyright © 2006 SmartyDevil.com - Dies Mies Jeschet Boenedoesef Douvema Enitemaus -
666