PHP Release 5.2.3


PHP 5.2.3 Release Announcement

The PHP development team would like to announce the immediate availability of PHP 5.2.3. This release continues to improve the security and the stability of the 5.X branch as well as addressing two regressions introduced by the previous 5.2 releases. These regressions relate to the timeout handling over non-blocking SSL connections and the lack of HTTP_RAW_POST_DATA in certain conditions. All users are encouraged to upgrade to this release.

Security Enhancements and Fixes in PHP 5.2.3:

  • Fixed an integer overflow inside chunk_split() (by Gerhard Wagner, CVE-2007-2872)
  • Fixed possible infinite loop in imagecreatefrompng. (by Xavier Roche, CVE-2007-2756)
  • Fixed ext/filter Email Validation Vulnerability (MOPB-45 by Stefan Esser, CVE-2007-1900)
  • Fixed bug #41492 (open_basedir/safe_mode bypass inside realpath()) (by bugs dot php dot net at chsc dot dk)
  • Improved fix for CVE-2007-1887 to work with non-bundled sqlite2 lib.
  • Added mysql_set_charset() to allow runtime altering of connection encoding.

The key improvements of PHP 5.2.3 include:

  • Improved compilation of heredocs and interpolated strings.
  • Optimized out a couple of per-request syscalls.
  • Optimized digest generation in md5() and sha1() functions.
  • Fixed bug #41236 (Regression in timeout handling of non-blocking SSL connections during reads and writes)
  • Fixed bug #39542 (Behavior of require/include different to < 5.2.0)
  • Fixed bug #41293 (Fixed creation of HTTP_RAW_POST_DATA when there is no default post handler)
  • Fixed bug #41347 (checkdnsrr() segfaults on empty hostname)
  • Fixed bug #41353 (crash in openssl_pkcs12_read() on invalid input)
  • Fixed bug #41403 (json_decode cannot decode floats if localeconv decimal_point is not '.')
  • Fixed bug #41421 (Uncaught exception from a stream wrapper segfaults)
  • Fixed bug #41504 (json_decode() incorrectly decodes JSON arrays with empty string keys).
  • Over 40 bug fixes.

For users upgrading from PHP 5.0 and PHP 5.1, an upgrade guide is available here, detailing the changes between those releases and PHP 5.2.3.

For a full list of changes in PHP 5.2.3, see the ChangeLog.

Source Code
Change Logs
added pdo
  • Added a 4th parameter flag to htmlspecialchars() and htmlentities() that makes the function not encode existing html entities. an associated array.
  • Added CURLOPT_TIMEOUT_MS and CURLOPT_CONNECTTIMEOUT_MS cURL constants.
  • Added --ini switch to CLI that prints out configuration file names.
  • Added mysql_set_charset() to allow runtime altering of connection encoding.
  • Implemented FR #41416 (getColumnMeta() should also return table name).
  • Fixed an integer overflow inside chunk_split(). Identified by Gerhard Wagner.
  • Fixed SOAP extension's handler() to work even when "always_populate_raw_post_data" is off.
  • Fixed possible infinite loop in imagecreatefrompng. (libgd #86) (by Xavier Roche, CVE-2007-2756).
  • Fixed ext/filter Email Validation Vulnerability (MOPB-45 by Stefan Esser).
  • Fixed altering $this via argument named "this".
  • Fixed PHP CLI usage of php.ini from the binary location.
  • Fixed segfault in strripos().
  • Fixed bug #41693 (scandir() allows empty directory names).
  • Fixed bug #41673 (json_encode breaks large numbers in arrays).
fixed bug #41525 (reflectionparameter
  • Fixed bug #41511 (Compile failure under IRIX 6.5.30 building md5.c).
  • Fixed bug #41504 (json_decode() incorrectly decodes JSON arrays with empty string keys).
  • Fixed bug #41492 (open_basedir/safe_mode bypass inside realpath()).
fixed bug #41477 (no arginfo about soapclient
  • Fixed bug #41455 (ext/dba/config.m4 pollutes global $LIBS and $LDFLAGS).
  • Fixed bug #41442 (imagegd2() under output control).
  • Fixed bug #41430 (Fatal error with negative values of maxlen parameter of file_get_contents()).
  • Fixed bug #41423 (PHP assumes wrongly that certain ciphers are enabled in OpenSSL).
  • Fixed bug #41421 (Uncaught exception from a stream wrapper segfaults).
  • Fixed bug #41403 (json_decode cannot decode floats if localeconv decimal_point is not '.').
  • Fixed bug #41401 (wrong unary operator precedence).
  • Fixed bug #41394 (dbase_create creates file with corrupted header).
  • Fixed bug #41390 (Clarify error message with invalid protocol scheme).
  • Fixed bug #41378 (fastcgi protocol lacks support for Reason-Phrase in "Status:" header).
  • Fixed bug #41374 (whole text concats values of wrong nodes).
  • Fixed bug #41358 (configure cannot determine SSL lib with libcurl >= 7.16.2).
  • Fixed bug #41353 (crash in openssl_pkcs12_read() on invalid input).
  • Fixed bug #41351 (Invalid opcode with foreach ($a[] as $b)).
  • Fixed bug #41347 (checkdnsrr() segfaults on empty hostname).
  • Fixed bug #41337 (WSDL parsing doesn't ignore non soap bindings).
fixed bug #41326 (writing empty tags with xmlwriter
  • Fixed bug #41321 (downgrade read errors in getimagesize() to E_NOTICE).
  • Fixed bug #41304 (compress.zlib temp files left).
  • Fixed bug #41293 (Fixed creation of HTTP_RAW_POST_DATA when there is no default post handler).
  • Fixed bug #41291 (FastCGI does not set SO_REUSEADDR).
  • Fixed gd build when used with freetype 1.x
  • Fixed bug #41287 (Namespace functions don't allow xmlns definition to be optional).
  • Fixed bug #41285 (Improved fix for CVE-2007-1887 to work with non-bundled sqlite2 lib).
  • Fixed bug #41283 (Bug with deserializing array key that are doubles or floats in wddx).
  • Fixed bug #41257 (lookupNamespaceURI does not work as expected).
  • Fixed bug #41236 (Regression in timeout handling of non-blocking SSL connections during reads and writes).
  • Fixed bug #41134 (zend_ts_hash_clean not thread-safe).
  • Fixed bug #41097 (ext/soap returning associative array as indexed without using WSDL).
  • Fixed bug #41004 (minOccurs="0" and null class member variable).
  • Fixed bug #39542 (Behavior of require/include different to < 5.2.0).
To Top