Skip to content

use proper DBI parameter passing to improve security#264

Merged
kylejohnson merged 1 commit intomasterfrom
improvezmpkg
Dec 13, 2013
Merged

use proper DBI parameter passing to improve security#264
kylejohnson merged 1 commit intomasterfrom
improvezmpkg

Conversation

@connortechnology
Copy link
Member

remark out call to zmupdate.pl -f

remark out call to zmupdate.pl -f
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why is this commented out?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

zmupdate -f simply reads info from the dB and turns around and writes it right back to the dB. It looks like user Stan added this back in 2011, but I don't know what his intent was. This same command was also part of the stock zm init script, but after discussing it with mastertheknife I commented it out (the one in the init file).

TLDR: This might be the cause of the Conig table corruption issue.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The thing is, if you are going to modify the Config Table, you have to exclusively lock it so that nothing reads in the meantime.

kylejohnson added a commit that referenced this pull request Dec 13, 2013
Use proper DBI parameter passing in zmpkg.pl to improve security
@kylejohnson kylejohnson merged commit c3c3cfb into master Dec 13, 2013
@connortechnology connortechnology deleted the improvezmpkg branch October 17, 2014 13:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants