That explains why there's such a multitude of such problems in various PHP programs -- and there is a huge number and variety -- but not why a library used by respected PHP software projects would have that kind of problem.

Comment on Re: The PHP Ghetto
by Ian Bicking


Agreed -- I was addressing the larger point of the overall quality level of most PHP code out there. But as mentioned above by jfj, this is hardly the exclusive domain of PHP - libpng had a huge hole[s], and check out the vendor list of products that lib made it into: http://www.kb.cert.org/vuls/id/388984 Yikes!

# ToddG