[imp] Much concern from IMP

Michael M Slusarz slusarz@bigworm.colorado.edu
Tue, 23 Jul 2002 10:48:37 -0600


Quoting Mike Barsalou <mbarsalou@aidea.org>:

| Is there much to be concerned about with regard to imp on this?
| 
| http://www.php.net/release_4_2_2.php
| 
| Mike

Yes - this affects anyone using PHP 4.2.0/4.2.1.  It is a security hole in 
the uploading of information from the web browser to the server (e.g. 
uploading attachments in IMP, uploading files in Gollem).  Everyone should 
upgrade regardless (as with any security patch).

michael

______________________________________________
Michael Slusarz [slusarz@bigworm.colorado.edu]
The University of Colorado at Boulder