hi,
On Mon, Mar 17, 2014 at 10:09 PM, Yasuo Ohgaki <[email protected]> wrote:
For one, I appreciate the effort that both of you put on the session management.
It seems that you are somehow alone to discuss this issue and slightly
in circle right now.
I would suggest two steps:
- sit down together for a chat and get your stuff together. It will by
far more efficient than mails
- write one or more RFCs to fix what should be fixed, how and why (see
next point :)
- provide more info about the actual critical security impact that
could be fixed by the changes
as of now, I failed to see any CVE related to what you are referring to
Cheers,
--
Pierre
@pierrejoye | http://www.libgd.org