Comment 28 for bug 11223

Revision history for this message
In , Florian Weimer (fw) wrote : Re: A backport of PHP fixes for 4.1.2

* Martin Schulze:

>> Huh? What about safe_mode? Does CVE officially declare safe_mode as
>> fundamentally insecure?
>
> Yes (except that it's not CVE who declared but vendor-sec).

Okay, this actually good news.

Shall I write a draft DSA and some documentation patches? Some of our
users rely on this feature and are not aware of its defects.