diff options
| author | Greg Beaver <cellog@php.net> | 2008-05-08 00:49:37 +0000 |
|---|---|---|
| committer | Greg Beaver <cellog@php.net> | 2008-05-08 00:49:37 +0000 |
| commit | a919e2f858e0d9f1247dca8e87bab5f8ad6ec09a (patch) | |
| tree | 988c4e5b01b31eb80562ba5b46e2d72f7aeff635 /scripts | |
| parent | 5576983a3e96d4b409a1192aeec69c7d503718f5 (diff) | |
| download | php-git-a919e2f858e0d9f1247dca8e87bab5f8ad6ec09a.tar.gz | |
fix serious logic error and potential security issue with phar_compiled_file and
phar_find_in_include_path. We were allowing data-based phars to be executed, and actually marking phar-based phar archives
without '.phar' in the name as data-based phars, which would allow modifying them even if phar.readonly=0. Add test for this sinister case
Diffstat (limited to 'scripts')
0 files changed, 0 insertions, 0 deletions
