php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Request #23513 security flaw: info posted on newsgroup
Submitted: 2003-05-06 14:00 UTC Modified: 2003-05-06 17:59 UTC
Votes:2
Avg. Score:5.0 ± 0.0
Reproduced:2 of 2 (100.0%)
Same Version:0 (0.0%)
Same OS:1 (50.0%)
From: jlindsey at guarded dot net Assigned:
Status: Closed Package: Feature/Change Request
PHP Version: 4.3.1 OS: linux
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: jlindsey at guarded dot net
New email:
PHP Version: OS:

 

 [2003-05-06 14:00 UTC] jlindsey at guarded dot net
After php compiles and runs its tests, there is an option to send the information to the php developers.  That option does not make it clear that the information will be posted on a public newsgroup, php.qa

Yaaaaay!  All the world can see detailed config info of one of my company's internal machines, as well as other swell info (like my email address).

Thanks php guys...that's great security!

Seriously...who thought this was a good idea?  Stop!  Stop it now!

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2003-05-06 15:23 UTC] rasmus@php.net
I have added a better disclaimer reminding people to use the
save feature and edit their report for sensitive data before sending it in if they are worried about that.
 [2003-05-06 17:54 UTC] jlindsey at guarded dot net
Uhm, a disclaimer is not enough.  No one reads them anyway.  Why does this info have to go to a totally public form?  Can't it go to a php-dev mailing list?
 [2003-05-06 17:59 UTC] rasmus@php.net
All our mailing lists are available via nntp and http on news.php.net.  The QA list this is sent to is a mailing list.
From a security perspective the level of publicity is irrelevant.  If you send out sensitive data to just a single external person you should consider that data compromised.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 15:00:01 2026 UTC