Bug#850158: [php-maint] Bug#850158: Use of uninitialized memory in unserialize()

2017-01-04 Thread Salvatore Bonaccorso
Hi Ondřej On Wed, Jan 04, 2017 at 03:24:22PM +0100, Ondřej Surý wrote: > Hi, > > any web application that allows passing unsanitized data to > unserialize() is doomed, so I don't really think that this requires > immediate attention. > > This will get fixed in a normal security cycle with next P

Bug#850158: [php-maint] Bug#850158: Use of uninitialized memory in unserialize()

2017-01-04 Thread Ondřej Surý
Hi, any web application that allows passing unsanitized data to unserialize() is doomed, so I don't really think that this requires immediate attention. This will get fixed in a normal security cycle with next PHP release (or I'll add the patch on top of next release). Cheers, -- Ondřej Surý K