[wp-trac] [WordPress Trac] #17375: Serialized option values broken for classes with Serializable interface

WordPress Trac noreply at wordpress.org
Fri May 8 16:29:40 UTC 2015


#17375: Serialized option values broken for classes with Serializable interface
--------------------------------+--------------------------
 Reporter:  hakre               |       Owner:  markjaquith
     Type:  defect (bug)        |      Status:  reviewing
 Priority:  normal              |   Milestone:  4.3
Component:  Options, Meta APIs  |     Version:  2.0.5
 Severity:  normal              |  Resolution:
 Keywords:  close               |     Focuses:
--------------------------------+--------------------------
Changes (by nacin):

 * keywords:  has-patch, dev-feedback => close


Comment:

 Replying to [comment:15 nacin]:
 > Any changes here need sign-off by the security team before continuing.

 I am almost positive we cannot make this change without directly adding an
 arbitrary code execution vulnerability.

 = *DO NOT COMMIT UNDER ANY CIRCUMSTANCES.* =

--
Ticket URL: <https://core.trac.wordpress.org/ticket/17375#comment:35>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list