Month of PHP bugs gets rolling
- 06 March, 2007 08:50
- Comments
Developer Stefan Esser has launched his Month of PHP Bugs project with 11 bugs in five days, including an old flaw reintroduced in a new version of PHP and several known bugs he says are unlikely ever to be fixed.
Esser and his collaborators published eight flaws in the first three days of the month, followed by another three on Sunday and Monday. Unlike similar, but unconnected, projects such as the Month of Kernel Bugs and the Month of Apple Bugs, "we do not enforce a one-vulnerability-per-day limit upon ourselves," Esser wrote on the site.
The project is designed to force PHP developers to improve security, and Esser kept up a steady stream of criticism of the way PHP security is handled. The three bugs published on the project's first day are those "that are already known but are not yet or will never be fixed", he said.
A cross-site scripting flaw, bug number eight, was disclosed in October 2005, fixed, but then reintroduced in PHP 4.4.3, Esser said.
The project focuses on the PHP standard distribution, but Esser included two "bonus" bugs that affect the Zend Platform, which runs on a web server, monitoring PHP applications and reporting on performance and possible problems.
Zend, which sponsors PHP development, has criticized Esser for his aggressive attitude toward PHP developers, but Esser said others have been supportive, with several developers volunteering their own zero-day flaws for publication.
"The reaction has been quite positive so far," he wrote in a blog post.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Why Encrypt? Securing Email without compromising communications.
- Seven Tips for Securing Mobile Workers
- Keeping up With Ever-Expanding Enterprise Data - 2010 IOUG Database Growth Survey
- Pay-As-You-Grow: Investment Protection and Elasticity for your Network
- How to Choose an SMB - Unified Communications as a Service (UCAAS) Solution
-
Customer service still dogs Telstra
-
Foxtel subscriber base grows
-
Obama's H-1B answer in forum may haunt him
-
NBN a pie in the sky: Morgan
-
Which tablet should I buy? iPad 2 vs Sony Tablet S
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 All-In-One Desk Reference for Dummies
-
MYOB Software for Dummies 6E Australian Edition
-
Windows 7 for Dummies® Dvd+book Bundle
-
Office 2007 for Dummies
-
Windows 7 for Seniors for Dummies®
-
Microsoft Office
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies®












Comments
Post new comment