Bug#315703: Bug#316590: woody backport now available for all cacti security issues

2005-07-19 Thread Sean Finney
and (hopefully,) a final update... On Tue, Jul 19, 2005 at 10:52:43AM +0200, Martin Schulze wrote: > > 2 is trickier. we could either repeat the process i'm about finished > > with wrt mysql_foo for all the functions that pass variables to > > mysql_foo, or we could do the sanity checking in the

Bug#315703: Bug#316590: woody backport now available for all cacti security issues

2005-07-19 Thread Martin Schulze
Sean Finney wrote: > On Tue, Jul 19, 2005 at 07:54:31AM +0200, Martin Schulze wrote: > > Ok, I'll wait. > > so, a 6 hour plane flight later, i've learned 3 things: > > 1 - there are a number of other variables that also need to be included. > 2 - there are a number of calls where variables are in

Bug#315703: Bug#316590: woody backport now available for all cacti security issues

2005-07-19 Thread Sean Finney
On Tue, Jul 19, 2005 at 07:54:31AM +0200, Martin Schulze wrote: > Ok, I'll wait. so, a 6 hour plane flight later, i've learned 3 things: 1 - there are a number of other variables that also need to be included. 2 - there are a number of calls where variables are indirectly passed to mysql_foo

Bug#315703: Bug#316590: woody backport now available for all cacti security issues

2005-07-15 Thread sean finney
On Thu, Jul 14, 2005 at 07:10:30PM +0200, Martin Schulze wrote: > Sean Finney wrote: > > i guess i didn't in the email updating this, but did so in sanitize.php > > itself: > > Yes, I saw that later. I hope, my tone wasn't too harsh. my skin is fairly thick :) > Yes, but the woody version does