PHP Release 5.2.4


PHP 5.2.4 Release Announcement

The PHP development team would like to announce the immediate availability of PHP 5.2.4. This release focuses on improving the stability of the PHP 5.2.X branch with over 120 various bug fixes in addition to resolving several low priority security bugs. All users of PHP are encouraged to upgrade to this release.

Security Enhancements and Fixes in PHP 5.2.4:

  • Fixed a floating point exception inside wordwrap() (Reported by Mattias Bengtsson)
  • Fixed several integer overflows inside the GD extension (Reported by Mattias Bengtsson)
  • Fixed size calculation in chunk_split() (Reported by Gerhard Wagner)
  • Fixed integer overflow in str[c]spn(). (Reported by Mattias Bengtsson)
  • Fixed money_format() not to accept multiple %i or %n tokens. (Reported by Stanislav Malyshev)
  • Fixed zend_alter_ini_entry() memory_limit interruption vulnerability. (Reported by Stefan Esser)
  • Fixed INFILE LOCAL option handling with MySQL extensions not to be allowed when open_basedir or safe_mode is active. (Reported by Mattias Bengtsson)
  • Fixed session.save_path and error_log values to be checked against open_basedir and safe_mode (CVE-2007-3378) (Reported by Maksymilian Arciemowicz)
  • Fixed a possible invalid read in glob() win32 implementation (CVE-2007-3806) (Reported by shinnai)
  • Fixed a possible buffer overflow in php_openssl_make_REQ (Reported by zatanzlatan at hotbrev dot com)
  • Fixed an open_basedir bypass inside glob() function (Reported by dr at peytz dot dk)
  • Fixed a possible open_basedir bypass inside session extension when the session file is a symlink (Reported by c dot i dot morris at durham dot ac dot uk)
  • Improved fix for MOPB-03-2007.
  • Corrected fix for CVE-2007-2872.

Key enhancements in PHP 5.2.4 include:

  • Upgraded PCRE to version 7.2
  • Added persistent connection status checker to pdo_pgsql.
  • Fixed oci8 and PDO_OCI extensions to allow configuring with Oracle 11g client libraries.
  • Fixed bug #41831 (pdo_sqlite prepared statements convert resources to strings).
  • Fixed bug #41770 (SSL: fatal protocol error due to buffer issues)
  • Fixed bug #41713 (Persistent memory consumption on win32 since 5.2)
  • Over 120 bug fixes.

For users upgrading from PHP 5.0 and PHP 5.1, an upgrade guide is available here, detailing the changes between those releases and PHP 5.2.4.

For a full list of changes in PHP 5.2.4, see the ChangeLog.

Source Code
Change Logs
added reflectionextension
  • Added PCRE_VERSION constant. (Tony) block for an extension.
implemented fr #41884 (reflectionclass
  • Fixed "Floating point exception" inside wordwrap().
  • Fixed several integer overflows in ImageCreate(), ImageCreateTrueColor(), ImageCopyResampled() and ImageFilledPolygon() reported by Mattias Bengtsson.
  • Fixed size calculation in chunk_split().
  • Fixed integer overflow in str[c]spn().
  • Fixed money_format() not to accept multiple %i or %n tokens.
  • Fixed zend_alter_ini_entry() memory_limit interruption vulnerability.
  • Fixed INFILE LOCAL option handling with MySQL extensions not to be allowed when open_basedir or safe_mode is active.
  • Fixed session.save_path and error_log values to be checked against open_basedir and safe_mode (CVE-2007-3378)
  • Fixed possible invalid read in glob() win32 implementation (CVE-2007-3806).
  • Improved fix for MOPB-03-2007.
  • Corrected fix for CVE-2007-2872.
  • Fixed possible crash in imagepsloadfont(), work around a bug in the pslib on Windows.
  • Fixed oci8 and PDO_OCI extensions to allow configuring with Oracle 11g client libraries.
  • Fixed EOF handling in case of reading from file opened in write only mode.
  • Fixed var_export() to use the new H modifier so that it can generate parseable PHP code for floats, independent of the locale.
  • Fixed regression introduced by the fix for the libgd bug #74.
  • Fixed SimpleXML's behavior when used with empty().
  • Fixed crash in OpenSSL extension because of non-string passphrase.
  • Fixed PECL Bug #11345 (PDO_OCI crash after National language Support "NLS" environment initialization error).
fixed bug #42848 (status
  • Fixed bug #42368 (Incorrect error message displayed by pg_escape_string).
  • Fixed bug #42365 (glob() crashes and/or accepts way too many flags).
  • Fixed Bug #42364 (Crash when using getRealPath with DirectoryIterator).
  • Fixed bug #42292 ($PHP_CONFIG not set for phpized builds).
  • Fixed bug #42261 (header wrong for date field).
  • Fixed bug #42259 (SimpleXMLIterator loses ancestry).
  • Fixed bug #42247 (ldap_parse_result() not defined under win32).
  • Fixed bug #42243 (copy() does not output an error when the first arg is a dir).
  • Fixed bug #42242 (sybase_connect() crashes).
  • Fixed bug #42237 (stream_copy_to_stream returns invalid values for mmaped streams).
  • Fixed bug #42233 (Problems with æøå in extract()).
  • Fixed bug #42222 (possible buffer overflow in php_openssl_make_REQ).
  • Fixed bug #42211 (property_exists() fails to find protected properties from a parent class).
  • Fixed bug #42208 (substr_replace() crashes when the same array is passed more than once).
  • Fixed bug #42198 (SCRIPT_NAME and PHP_SELF truncated when inside a userdir and using PATH_INFO).
  • Fixed bug #42195 (C++ compiler required always).
  • Fixed bug #42183 (classmap causes crash in non-wsdl mode).
  • Fixed bug #42173 (oci8 INTERVAL and TIMESTAMP type fixes).
  • Fixed bug #42151 (__destruct functions not called after catching a SoapFault exception).
  • Fixed bug #42142 (substr_replace() returns FALSE when length > string length).
  • Fixed bug #42135 (Second call of session_start() causes creation of SID).
  • Fixed bug #42134 (oci_error() returns false after oci_new_collection() fails).
  • Fixed bug #42119 (array_push($arr,&$obj) doesn't work with zend.ze1_compatibility_mode On).
  • Fixed bug #42117 (bzip2.compress loses data in internal buffer).
  • Fixed bug #42112 (deleting a node produces memory corruption).
  • Fixed bug #42107 (sscanf broken when using %2$s format parameters).
  • Fixed bug #42090 (json_decode causes segmentation fault).
  • Fixed bug #42082 (NodeList length zero should be empty).
  • Fixed bug #42072 (No warning message for clearstatcache() with arguments).
  • Fixed bug #42071 (ini scanner allows using NULL as option name).
  • Fixed bug #42027 (is_file() / is_dir() matches file/dirnames with wildcard char or trailing slash in Windows).
  • Fixed bug #42019 (configure option --with-adabas=DIR does not work).
fixed bug #42015 (ldap_rename()
  • Fixed bug #42009 (is_a() and is_subclass_of() should NOT call autoload, in the same way as "instanceof" operator).
  • Fixed bug #41989 (move_uploaded_file() & relative path in ZTS mode).
  • Fixed bug #41984 (Hangs on large SoapClient requests).
  • Fixed bug #41983 (Error Fetching http headers terminated by '\n').
  • Fixed bug #41973 (--with-ldap=shared fails with LDFLAGS="-Wl,--as-needed").
fixed bug #41971 (pdostatement
  • Fixed bug #41964 (strtotime returns a timestamp for non-time string of pattern '(A|a) .+').
  • Fixed bug #41961 (Ensure search for hidden private methods does not stray from class hierarchy).
  • Fixed bug #41947 (SimpleXML incorrectly registers empty strings asnamespaces).
  • Fixed bug #41929 (Foreach on object does not iterate over all visible properties).
  • Fixed bug #41919 (crash in string to array conversion).
  • Fixed bug #41909 (var_export() is locale sensitive when exporting float values).
  • Fixed bug #41908 (CFLAGS="-Os" ./configure --enable-debug fails).
fixed bug #41861 (simplexml
  • Fixed bug #41845 (pgsql extension does not compile with PostgreSQL <7.4).
  • Fixed bug #41844 (Format returns incorrect number of digits for negative years -0001 to -0999).
  • Fixed bug #41842 (Cannot create years < 0100 & negative years with date_create or new DateTime).
  • Fixed bug #41833 (addChild() on a non-existent node, no node created, getName() segfaults).
  • Fixed bug #41831 (pdo_sqlite prepared statements convert resources to strings).
  • Fixed bug #41815 (Concurrent read/write fails when EOF is reached).
  • Fixed bug #41813 (segmentation fault when using string offset as an object).
  • Fixed bug #41795 (checkdnsrr does not support DNS_TXT type).
  • Fixed bug #41773 (php_strip_whitespace() sends headers with errors suppressed).
fixed bug #41770 (ssl
  • Fixed bug #41765 (Recode crashes/does not work on amd64).
  • Fixed bug #41724 (libxml_get_last_error() - errors service request scope).
  • Fixed bug #41717 (imagepolygon does not respect thickness).
  • Fixed bug #41713 (Persistent memory consumption on win32 since 5.2).
  • Fixed bug #41711 (NULL temporary lobs not supported in OCI8).
  • Fixed bug #41709 (strtotime() does not handle 00.00.0000).
  • Fixed bug #41698 (float parameters truncated to integer in prepared statements).
  • Fixed bug #41692 (ArrayObject shows weird behavior in respect to inheritance).
fixed bug #41691 (arrayobject
  • Fixed bug #41686 (Omitting length param in array_slice not possible).
  • Fixed bug #41685 (array_push() fails to warn when next index is already occupied).
  • Fixed bug #41655 (open_basedir bypass via glob()).
  • Fixed bug #41640 (get_class_vars produces error on class constants).
  • Fixed bug #41635 (SoapServer and zlib.output_compression with FastCGI result in major slowdown).
  • Fixed bug #41633 (Crash instantiating classes with self-referencing constants).
  • Fixed bug #41630 (segfault when an invalid color index is present in the image data). (Reported by Elliot <wccoder@gmail dot com>)
  • Fixed bug #41628 (PHP settings leak between Virtual Hosts in Apache 1.3).
  • Fixed bug #41608 (segfault on a weird code with objects and switch()).
  • Fixed bug #41600 (url rewriter tags doesn't work with namespaced tags).
  • Fixed bug #41596 (Fixed a crash inside pdo_pgsql on some non-well-formed SQL queries).
  • Fixed bug #41594 (OCI8 statement cache is flushed too frequently).
  • Fixed bug #41582 (SimpleXML crashes when accessing newly created element).
  • Fixed bug #41576 (configure failure when using --without-apxs or some other SAPIs disabling options).
  • Fixed bug #41567 (json_encode() double conversion is inconsistent with PHP).
  • Fixed bug #41566 (SOAP Server not properly generating href attributes).
fixed bug #41555 (configure failure
  • Fixed bug #41527 (WDDX deserialize numeric string array key).
fixed bug #41523 (strtotime('0000-00-00 00
  • Fixed bug #41518 (file_exists() warns of open_basedir restriction on non-existent file).
  • Fixed bug #41445 (parse_ini_file() has a problem with certain types of integer as sections).
fixed bug #41433 (dba
  • Fixed bug #41372 (Internal pointer of source array resets during array copying).
  • Fixed bug #41350 (my_thread_global_end() error during request shutdown on Windows).
  • Fixed bug #41278 (get_loaded_extensions() should list Zend extensions).
  • Fixed bug #41127 (Memory leak in ldap_{first|next}_attribute functions).
  • Fixed bug #40757 (get_object_vars get nothing in child class).
  • Fixed bug #40705 (Iterating within function moves original array pointer).
  • Fixed bug #40509 (key() function changed behaviour if global array is used within function).
  • Fixed bug #40419 (Trailing slash in CGI request does not work).
  • Fixed bug #39330 (apache2handler does not call shutdown actions before apache child die).
  • Fixed bug #39291 (ldap_sasl_bind() misses the sasl_authc_id parameter).
  • Fixed bug #37715 (array pointers resetting on copy).
  • Fixed bug #37273 (Symlinks and mod_files session handler allow open_basedir bypass).
  • Fixed bug #36492 (Userfilters can leak buckets).
  • Fixed bugs #36796, #36918, #41371 (stream_set_blocking() does not work).
  • Fixed bug #35981 (pdo-pgsql should not use pkg-config when not present).
  • Fixed bug #31892 (PHP_SELF incorrect without cgi.fix_pathinfo, but turning on screws up PATH_INFO).
  • Fixed bug #21197 (socket_read() outputs error with PHP_NORMAL_READ).
To Top