PHP Release 5.2.12


PHP 5.2.12 Release Announcement

The PHP development team would like to announce the immediate availability of PHP 5.2.12. This release focuses on improving the stability of the PHP 5.2.x branch with over 60 bug fixes, some of which are security related. All users of PHP 5.2 are encouraged to upgrade to this release.

Security Enhancements and Fixes in PHP 5.2.12:

  • Fixed a safe_mode bypass in tempnam() identified by Grzegorz Stachowiak. (CVE-2009-3557, Rasmus)
  • Fixed a open_basedir bypass in posix_mkfifo() identified by Grzegorz Stachowiak. (CVE-2009-3558, Rasmus)
  • Added "max_file_uploads" INI directive, which can be set to limit the number of file uploads per-request to 20 by default, to prevent possible DOS via temporary file exhaustion, identified by Bogdan Calin. (CVE-2009-4017, Ilia)
  • Added protection for $_SESSION from interrupt corruption and improved "session.save_path" check, identified by Stefan Esser. (CVE-2009-4143, Stas)
  • Fixed bug #49785 (insufficient input string validation of htmlspecialchars()). (CVE-2009-4142, Moriyoshi, hello at iwamot dot com)

Key enhancements in PHP 5.2.12 include:

  • Fixed unnecessary invocation of setitimer when timeouts have been disabled. (Arvind Srinivasan)
  • Fixed crash in com_print_typeinfo when an invalid typelib is given. (Pierre)
  • Fixed crash in SQLiteDatabase::ArrayQuery() and SQLiteDatabase::SingleQuery() when calling using Reflection. (Felipe)
  • Fixed crash when instantiating PDORow and PDOStatement through Reflection. (Felipe)
  • Fixed memory leak in openssl_pkcs12_export_to_file(). (Felipe)
  • Fixed bug #50207 (segmentation fault when concatenating very large strings on 64bit linux). (Ilia)
  • Fixed bug #50162 (Memory leak when fetching timestamp column from Oracle database). (Felipe)
  • Fixed bug #50006 (Segfault caused by uksort()). (Felipe)
  • Fixed bug #50005 (Throwing through Reflection modified Exception object makes segmentation fault). (Felipe)
  • Fixed bug #49174 (crash when extending PDOStatement and trying to set queryString property). (Felipe)
  • Fixed bug #49098 (mysqli segfault on error). (Rasmus)
  • Over 50 other bug fixes.

For users upgrading from PHP 5.0 and PHP 5.1, an upgrade guide is available here, detailing the changes between those releases and PHP 5.2.12.

For a full list of changes in PHP 5.2.12, see the ChangeLog.

Source Code
Change Logs
fixed crash in sqlitedatabase
  • Fixed a open_basedir bypass in posix_mkfifo() identified by Grzegorz Stachowiak. (Rasmus) when calling using Reflection.
  • Fixed crash when instantiating PDORow and PDOStatement through Reflection.
  • Fixed memory leak in openssl_pkcs12_export_to_file().
  • Fixed bug #50445 (PDO-ODBC stored procedure call from Solaris 64-bit causes segfault).
  • Fixed bug #50345 (nanosleep not detected properly on some solaris versions).
  • Fixed bug #50323 (Allow use of ; in values via ;; in PDO DSN).
  • Fixed bug #50285 (xmlrpc does not preserve keys in encoded indexed arrays).
  • Fixed bug #50282 (xmlrpc_encode_request() changes object into array in calling function).
  • Fixed bug #50266 (conflicting types for llabs).
  • Fixed bug #50255 (isset() and empty() silently casts array to object).
  • Fixed bug #50219 (soap call Segmentation fault on a redirected url).
  • Fixed bug #50209 (Compiling with libedit cannot find readline.h).
  • Fixed bug #50207 (segmentation fault when concatenating very large strings on 64bit linux).
  • Fixed bug #50195 (pg_copy_to() fails when table name contains schema.
  • Fixed bug #50185 (ldap_get_entries() return false instead of an empty array when there is no error).
  • Fixed bug #50174 (Incorrectly matched docComment).
  • Fixed bug #50168 (FastCGI fails with wrong error on HEAD request to non-existent file).
  • Fixed bug #50162 (Memory leak when fetching timestamp column from Oracle database).
  • Fixed bug #50158 (FILTER_VALIDATE_EMAIL fails with valid addresses containing = or ?).
  • Fixed bug #50073 (parse_url() incorrect when ? in fragment).
  • Fixed bug #50006 (Segfault caused by uksort()).
  • Fixed bug #50005 (Throwing through Reflection modified Exception object makes segmentation fault).
  • Fixed bug #49990 (SNMP3 warning message about security level printed twice).
  • Fixed bug #49985 (pdo_pgsql prepare() re-use previous aborted transaction).
  • Fixed bug #49972 (AppendIterator undefined function crash).
  • Fixed bug #49921 (Curl post upload functions changed).
  • Fixed bug #49855 (import_request_variables() always returns NULL).
  • Fixed bug #49847 (exec() fails to return data inside 2nd parameter, given output lines >4095 bytes).
  • Fixed bug #49809 (time_sleep_until() is not available on OpenSolaris).
  • Fixed bug #49785 (insufficient input string validation of htmlspecialchars()).
  • Fixed bug #49757 (long2ip() can return wrong value in a multi-threaded applications).
  • Fixed bug #49738 (calling mcrypt() after mcrypt_generic_deinit() crashes).
fixed bug #49719 (reflectionclass
  • Fixed bug #49698 (Unexpected change in strnatcasecmp()).
  • Fixed bug #49677 (ini parser crashes with apache2 and using ${something} ini variables).
  • Fixed bug #49660 (libxml 2.7.3+ limits text nodes to 10MB).
  • Fixed bug #49647 (DOMUserData does not exist).
  • Fixed bug #49630 (imap_listscan() function missing).
  • Fixed bug #49627 (error_log to specified file does not log time according to date.timezone).
  • Fixed bug #49578 (make install-pear fails).
  • Fixed bug #49536 (mb_detect_encoding() returns incorrect results when mbstring.strict_mode is turned on).
  • Fixed bug #49531 (CURLOPT_INFILESIZE sometimes causes warning "CURLPROTO_FILE cannot be set").
  • Fixed bug #49528 (UTF-16 strings prefixed by BOMs wrongly converted).
  • Fixed bug #49521 (PDO fetchObject sets values before calling constructor).
  • Fixed bug #49517 (cURL's CURLOPT_FILE prevents file from being deleted after fclose()).
  • Fixed bug #49472 (Constants defined in Interfaces can be overridden).
  • Fixed bug #49354 (mb_strcut() cuts wrong length when offset is in the middle of a multibyte character).
  • Fixed bug #49332 (Build error with Snow Leopard).
  • Fixed bug #49244 (Floating point NaN cause garbage characters).
  • Fixed bug #49174 (crash when extending PDOStatement and trying to set queryString property).
  • Fixed bug #49098 (mysqli segfault on error).
  • Fixed bug #48805 (IPv6 socket transport is not working).
fixed bug #48764 (pdo_pgsql
  • Fixed bug #47848 (importNode doesn't preserve attribute namespaces).
  • Fixed bug #45120 (PDOStatement->execute() returns true then false for same statement).
  • Fixed bug #34852 (Failure in odbc_exec() using oracle-supplied odbc driver).
To Top