Comment 0 for bug 1594041

Revision history for this message
Lukas Reschke (lukasreschke) wrote : PHP Security Bug #68978 XSS in header() with Internet Explorer has not been backported

The PHP Security Bug #68978 (https://bugs.php.net/bug.php?id=68978) has not been backported to Trusty. It has been included with PHP 5.5.22 in February 2015.

The patch can be found at https://github.com/php/php-src/commit/996faf964bba1aec06b153b370a7f20d3dd2bb8b

We'd appreciate if this patch could be backported to Trusty to prevent PHP applications from being insecure against header injections in Internet Explorer.