[imp] PHP security

Jan Schneider jan@horde.org
Wed, 27 Feb 2002 16:39:41 +0100


Zitat von "Donatas V." <vyzard@yahoo.com>:

> Look:
> http://security.e-matters.de/advisories/012002.html
> 
> I am not a PHP programmer,so how imp uploads
> attachments?Maybe it can be exploitable?
> Should people using IMP begin to worry?

Of course IMP just uses the PHP functionality for handling file uploads. So 
everyone using any PHP application that incorporates file uploads (like 
IMP) should update to be on the safe side.

>From php.net: "All users of PHP are strongly encouraged to either upgrade 
to PHP 4.1.2, or install the patch (available for PHP 3.0.18, 4.0.6 and 
4.1.0/4.1.1)."

Jan.

--
http://www.horde.org - The Horde Project
http://www.ammma.de - discover your knowledge
http://www.tip4all.de - Deine private Tippgemeinschaft