4.1 has reached end-of-life and will no longer receive
bugfixes or security patches from the PHP Project.
Some downstream distributions may still continue to provide
backported fixes for a time, depending on their support policy.
For more information please see our
support policy.
The latest release of PHP 4.1 is
4.1.2.
PHP 4.1.0 Release Announcement
After a lengthy QA process, PHP 4.1.0 is finally out!
[ Version Française ]
PHP 4.1.0 includes several other key improvements:
- A new input interface for improved security (read below)
- Highly improved performance in general
-
Revolutionary performance and stability improvements under
Windows. The multithreaded server modules under Windows (ISAPI,
Apache, etc.) perform as much as 30 times faster under load! We
want to thank Brett Brewer and his team in Microsoft for working
with us to improve PHP for Windows.
-
Versioning support for extensions. Right now it's barely being
used, but the infrastructure was put in place to support separate
version numbers for different extensions. The negative side effect
is that loading extensions that were built against old versions of
PHP will now result in a crash, instead of in a nice clear message.
Make sure you only use extensions built with PHP 4.1.0.
- Turn-key output compression support
- LOTS of fixes and new functions
As some of you may notice, this version is quite historic, as it's
the first time in history we actually incremented the middle digit! :)
The two key reasons for this unprecedented change were the new input
interface, and the broken binary compatibility of modules due to the
versioning support.
Following is a description of the new input mechanism. For a full list of
changes in PHP 4.1.0, see the ChangeLog.
SECURITY: NEW INPUT MECHANISM
First and foremost, it's important to stress that regardless of
anything you may read in the following lines, PHP 4.1.0 still
supports the old input mechanisms from older versions.
Old applications should go on working fine without modification!
Now that we have that behind us, let's move on :)
For various reasons, PHP setups which rely on register_globals
being on (i.e., on form, server and environment variables becoming
a part of the global namespace, automatically) are very often
exploitable to various degrees. For example, the piece of code: