[Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data

John Bond john.r.bond at gmail.com
Tue Apr 4 14:29:26 BST 2006


On 3/29/06, Jeff Rosowski <rosowskij at ie.ymp.gov> wrote:

> It also doesn't affect all versions of PHP.  on 5.0.5, it returns \0
> followed by however many Ss you put after it. And your right you wouldn't
> trust user imput like that.
>
> _______________________________________________

I get this behaviour on php v5.0.4 on windows box




Full-Disclosure is hosted and sponsored by Secunia.