Hi everybody!

I want to tell that pretty nasty bug was discovered in PHP (all tested=20
versions were vulnerable). I do not want to disclose much details as it may=
=20
hurt many websites. I expect PHP team to make patch first.

There is simple way to protect yourself against this bug if you put some co=
de=20
in beginning of every source code looking for weird ASCII bytes before any=
=20
other code. Make some kind of "white-list" for characters you allow and den=
y=20
everything else.

More details to come when we have PHP patches distributed with major=20
distributions. I might disclose details before to some IDS vendor or other=
=20
trusted party.

T=F5nu