5.3 has reached end-of-life and will no longer receive
bugfixes or security patches from the PHP Project.
Some downstream distributions may still continue to provide
backported fixes for a time, depending on their support policy.
For more information please see our
support policy.
The latest release of PHP 5.3 is
5.3.29.
PHP 5.3.6 Release Announcement
The PHP development team would like to announce the immediate
availability of PHP 5.3.6. This release focuses on improving the
stability of the PHP 5.3.x branch with over 60 bug fixes, some of which
are security related.
Security Enhancements and Fixes in PHP 5.3.6:
- Enforce security in the fastcgi protocol parsing with fpm SAPI.
- Fixed bug #54247 (format-string vulnerability on Phar). (CVE-2011-1153)
- Fixed bug #54193 (Integer overflow in shmop_read()). (CVE-2011-1092)
- Fixed bug #54055 (buffer overrun with high values for precision ini setting).
- Fixed bug #54002 (crash on crafted tag in exif). (CVE-2011-0708)
- Fixed bug #53885 (ZipArchive segfault with FL_UNCHANGED on empty archive). (CVE-2011-0421)
Key enhancements in PHP 5.3.6 include:
- Upgraded bundled Sqlite3 to version 3.7.4.
- Upgraded bundled PCRE to version 8.11.
- Added ability to connect to HTTPS sites through proxy with basic authentication using stream_context/http/header/Proxy-Authorization.
- Added options to debug backtrace functions.
- Changed default value of ini directive serialize_precision from 100 to 17.
- Fixed Bug #53971 (isset() and empty() produce apparently spurious runtime error).
- Fixed Bug #53958 (Closures can't 'use' shared variables by value and by reference).
- Fixed bug #53577 (Regression introduced in 5.3.4 in open_basedir with a trailing forward slash).
- Over 60 other bug fixes.
Windows users: please mind that we do no longer provide builds created
with Visual Studio C++ 6. It is impossible to maintain a high quality
and safe build of PHP for Windows using this unmaintained compiler.
For Apache SAPIs (php5_apache2_2.dll), be sure that you use a Visual
Studio C++ 9 version of Apache. We recommend the Apache builds as provided
by ApacheLounge. For any other
SAPI (CLI, FastCGI via mod_fcgi, FastCGI with IIS or other FastCGI capable
server), everything works as before. Third party extension providers
must rebuild their extensions to make them compatible and loadable with
the Visual Studio C++9 builds that we now provide.
All PHP users should note that the PHP 5.2 series is NOT supported
anymore. All users are strongly encouraged to upgrade to PHP 5.3.6.
zend engine
- Upgraded bundled PCRE to version 8.11.
- Indirect reference to $this fails to resolve if direct $this is never used in method.
- Added options to debug backtrace functions.
- Fixed bug numerous crashes due to setlocale (crash on error, pcre, mysql etc.) on Windows in thread safe mode.
- Fixed Bug #53971 (isset() and empty() produce apparently spurious runtime error).
- Fixed Bug #53958 (Closures can't 'use' shared variables by value and by reference).
- Fixed Bug #53629 (memory leak inside highlight_string()).
- Fixed Bug #51458 (Lack of error context with nested exceptions).
- Fixed Bug #47143 (Throwing an exception in a destructor causes a fatal error).
- Fixed bug #43512 (same parameter name can be used multiple times in method/function definition).
core
- Added ability to connect to HTTPS sites through proxy with basic authentication using stream_context/http/header/Proxy-Authorization
- Changed default value of ini directive serialize_precision from 100 to 17.
- Fixed bug #54055 (buffer overrun with high values for precision ini setting).
- Fixed bug #53959 (reflection data for fgetcsv out-of-date).
- Fixed bug #53577 (Regression introduced in 5.3.4 in open_basedir with a trailing forward slash).
- Fixed bug #53682 (Fix compile on the VAX).
- Fixed bug #48484 (array_product() always returns 0 for an empty array).
- Fixed bug #48607 (fwrite() doesn't check reply from ftp server before exiting).
calendar extension
- Fixed bug #53574 (Integer overflow in SdnToJulian, sometimes leading to segfault).
dom extension
- Implemented FR #39771 (Made DOMDocument::saveHTML accept an optional DOMNode like DOMDocument::saveXML).
datetime extension
- Fixed a bug in DateTime->modify() where absolute date/time statements had no effect.
- Fixed bug #53729 (DatePeriod fails to initialize recurrences on 64bit big-endian systems).
- Fixed bug #52808 (Segfault when specifying interval as two dates).
- Fixed bug #52738 (Can't use new properties in class extended from DateInterval).
- Fixed bug #52290 (setDate, setISODate, setTime works wrong when DateTime created from timestamp).
- Fixed bug #52063 (DateTime constructor's second argument doesn't have a null default value).
exif extension
- Fixed bug #54002 (crash on crafted tag, reported by Luca Carettoni). (Pierre)
filter extension
- Fixed bug #53924 (FILTER_VALIDATE_URL doesn't validate port number).
- Fixed bug #53150 (FILTER_FLAG_NO_RES_RANGE is missing some IP ranges).
- Fixed bug #52209 (INPUT_ENV returns NULL for set variables (CLI)).
- Fixed bug #47435 (FILTER_FLAG_NO_RES_RANGE don't work with ipv6).
fileinfo extension
- Fixed bug #54016 (finfo_file() Cannot determine filetype in archives).
- Gettext
- Fixed bug #53837 (_() crashes on Windows when no LANG or LANGUAGE environment variable are set).
imap extension
- Implemented FR #53812 (get MIME headers of the part of the email).
- Fixed bug #53377 (imap_mime_header_decode() doesn't ignore \t during long MIME header unfolding).
intl extension
- Fixed bug #53612 (Segmentation fault when using cloned several intl objects).
- Fixed bug #53512 (NumberFormatter::setSymbol crash on bogus $attr values).
- Implemented clone functionality for number, date & message formatters. .
json extension
- Fixed bug #53963 (Ensure error_code is always set during some failed decodings).
- mysqlnd
- Fixed problem with always returning 0 as num_rows for unbuffered sets.
mysql improved extension
- Added 'db' and 'catalog' keys to the field fetching functions (FR #39847).
- Fixed buggy counting of affected rows when using the text protocol. The collected statistics were wrong when multi_query was used with mysqlnd
- Fixed bug #53795 (Connect Error from MySqli (mysqlnd) when using SSL).
- Fixed bug #53503 (mysqli::query returns false after successful LOAD DATA query).
- Fixed bug #53425 (mysqli_real_connect() ignores client flags when built to call libmysql).
openssl extension
- Fixed stream_socket_enable_crypto() not honoring the socket timeout in server mode.
- Fixed bug #54060 (Memory leaks when openssl_encrypt).
- Fixed bug #54061 (Memory leaks when openssl_decrypt).
- Fixed bug #53592 (stream_socket_enable_crypto() busy-waits in client mode).
- Implemented FR #53447 (Cannot disable SessionTicket extension for servers that do not support it) by adding a no_ticket SSL context option.
pdo mysql driver
- Fixed bug #53551 (PDOStatement execute segfaults for pdo_mysql driver).
- Implemented FR #47802 (Support for setting character sets in DSN strings).
pdo oracle driver
- Fixed bug #39199 (Cannot load Lob data with more than 4000 bytes on ORACLE 10).
pdo postgresql driver
- Fixed bug #53517 (segfault in pgsql_stmt_execute() when postgres is down).
phar extension
- Fixed bug #54247 (format-string vulnerability on Phar). (Felipe)
- Fixed bug #53541 (format string bug in ext/phar).
- Fixed bug #53898 (PHAR reports invalid error message, when the directory does not exist).
php-fpm sapi
- Enforce security in the fastcgi protocol parsing.
- Fixed bug #53777 (php-fpm log format now match php_error log format).
- Fixed bug #53527 (php-fpm --test doesn't set a valuable return value).
- Fixed bug #53434 (php-fpm slowlog now also logs the original request).
readline extension
- Fixed bug #53630 (Fixed parameter handling inside readline() function).
reflection extension
- Fixed bug #53915 (ReflectionClass::getConstant(s) emits fatal error on constants with self::).
shmop extension
- Fixed bug #54193 (Integer overflow in shmop_read()). (Felipe) Reported by Jose Carlos Norte <jose at eyeos dot org>
snmp extension
- Fixed bug #51336 (snmprealwalk (snmp v1) does not handle end of OID tree correctly).
soap extension
- Fixed possible crash introduced by the NULL poisoning patch.
spl extension
- Fixed memory leak in DirectoryIterator::getExtension() and SplFileInfo::getExtension().
- Fixed bug #53914 (SPL assumes HAVE_GLOB is defined).
- Fixed bug #53515 (property_exists incorrect on ArrayObject null and 0 values).
- Fixed bug #49608 (Using CachingIterator on DirectoryIterator instance segfaults).
- Added SplFileInfo::getExtension(). FR #48767.
sqlite3 extension
- Fixed memory leaked introduced by the NULL poisoning patch.
- Fixed memory leak on SQLite3Result and SQLite3Stmt when assigning to a reference.
- Add SQlite3_Stmt::readonly() for checking if a statement is read only.
- Implemented FR #53466 (SQLite3Result::columnType() should return false after all of the rows have been fetched).
streams
- Fixed bug #54092 (Segmentation fault when using HTTP proxy with the FTP wrapper).
- Fixed bug #53913 (Streams functions assume HAVE_GLOB is defined).
- Fixed bug #53903 (userspace stream stat callback does not separate the elements of the returned array before converting them).
- Implemented FR #26158 (open arbitrary file descriptor with fopen).
- Tokenizer Extension
- Fixed bug #54089 (token_get_all() does not stop after __halt_compiler).
xsl extension
- Fixed memory leaked introduced by the NULL poisoning patch.
zip extension
- Added the filename into the return value of stream_get_meta_data().
- Fixed bug #53923 (Zip functions assume HAVE_GLOB is defined).
- Fixed bug #53893 (Wrong return value for ZipArchive::extractTo()).
- Fixed bug #53885 (ZipArchive segfault with FL_UNCHANGED on empty archive). (Stas, Maksymilian Arciemowicz).
- Fixed bug #53854 (Missing constants for compression type).
- Fixed bug #53603 (ZipArchive should quiet stat errors).
- Fixed bug #53579 (stream_get_contents() segfaults on ziparchive streams).
- Fixed bug #53568 (swapped memset arguments in struct initialization).
- Fixed bug #53166 (Missing parameters in docs and reflection definition).
- Fixed bug #49072 (feof never returns true for damaged file in zip).