PHP Release 5.3.9


PHP 5.3.9 Release Announcement

The PHP development team would like to announce the immediate availability of PHP 5.3.9. This release focuses on improving the stability of the PHP 5.3.x branch with over 90 bug fixes, some of which are security related.

Security Enhancements and Fixes in PHP 5.3.9:

  • Added max_input_vars directive to prevent attacks based on hash collisions. (CVE-2011-4885)
  • Fixed bug #60150 (Integer overflow during the parsing of invalid exif header). (CVE-2011-4566)

Key enhancements in PHP 5.3.9 include:

  • Fixed bug #55475 (is_a() triggers autoloader, new optional 3rd argument to is_a and is_subclass_of).
  • Fixed bug #55609 (mysqlnd cannot be built shared)
  • Many changes to the FPM SAPI module

All users are strongly encouraged to upgrade to PHP 5.3.9.

Source Code
Change Logs
core
  • Added max_input_vars directive to prevent attacks based on hash collisions (CVE-2011-4885) .
  • Fixed bug #60205 (possible integer overflow in content_length).
  • Fixed bug #60139 (Anonymous functions create cycles not detected by the GC).
  • Fixed bug #60138 (GC crash with referenced array in RecursiveArrayIterator) .
  • Fixed bug #60120 (proc_open's streams may hang with stdin/out/err when the data exceeds or is equal to 2048 bytes).
  • Fixed bug #60099 (__halt_compiler() works in braced namespaces).
  • Fixed bug #60019 (Function time_nanosleep() is undefined on OS X).
  • Fixed bug #55874 (GCC does not provide __sync_fetch_and_add on some archs).
  • Fixed bug #55798 (serialize followed by unserialize with numeric object prop. gives integer prop).
  • Fixed bug #55749 (TOCTOU issue in getenv() on Windows builds).
  • Fixed bug #55707 (undefined reference to `__sync_fetch_and_add_4' on Linux parisc).
  • Fixed bug #55674 (fgetcsv & str_getcsv skip empty fields in some tab-separated records).
  • Fixed bug #55649 (Undefined function Bug()).
  • Fixed bug #55622 (memory corruption in parse_ini_string).
  • Fixed bug #55576 (Cannot conditionally move uploaded file without race condition).
  • Fixed bug #55510: $_FILES 'name' missing first character after upload.
  • Fixed bug #55509 (segfault on x86_64 using more than 2G memory).
  • Fixed bug #55504 (Content-Type header is not parsed correctly on HTTP POST request).
  • Fixed bug #55475 (is_a() triggers autoloader, new optional 3rd argument to is_a and is_subclass_of).
  • Fixed bug #52461 (Incomplete doctype and missing xmlns).
  • Fixed bug #55366 (keys lost when using substr_replace an array).
  • Fixed bug #55273 (base64_decode() with strict rejects whitespace after pad).
  • Fixed bug #52624 (tempnam() by-pass open_basedir with nonnexistent directory).
  • Fixed bug #50982 (incorrect assumption of PAGE_SIZE size).
  • Fixed invalid free in call_user_method() function.
  • Fixed bug #43200 (Interface implementation / inheritence not possible in abstract classes).
bcmath
  • Fixed bug #60377 (bcscale related crashes on 64bits platforms).
calendar
  • Fixed bug #55797 (Integer overflow in SdnToGregorian leads to segfault (in optimized builds).
curl
  • Fixed bug #60439 (curl_copy_handle segfault when used with CURLOPT_PROGRESSFUNCTION).
  • Fixed bug #54798 (Segfault when CURLOPT_STDERR file pointer is closed before calling curl_exec).
  • Fixed issues were curl_copy_handle() would sometimes lose copied preferences.
datetime
  • Fixed bug #60373 (Startup errors with log_errors on cause segfault).
  • Fixed bug #60236 (TLA timezone dates are not converted properly from timestamp).
  • Fixed bug #55253 (DateTime::add() and sub() result -1 hour on objects with time zone type 2).
  • Fixed bug #54851 (DateTime::createFromFormat() doesn't interpret "D").
  • Fixed bug #53502 (strtotime with timezone memory leak).
  • Fixed bug #52062 (large timestamps with DateTime::getTimestamp and DateTime::setTimestamp).
  • Fixed bug #51994 (date_parse_from_format is parsing invalid date using 'yz' format).
  • Fixed bug #52113 (Seg fault while creating (by unserialization) DatePeriod).
  • Fixed bug #48476 (cloning extended DateTime class without calling parent::__constr crashed PHP).
exif
  • Fixed bug #60150 (Integer overflow during the parsing of invalid exif header). (CVE-2011-4566)
fileinfo
  • Fixed bug #60094 (C++ comment fails in c89).
  • Fixed possible memory leak in finfo_open().
  • Fixed memory leak when calling the Finfo constructor twice.
filter
  • Fixed Bug #55478 (FILTER_VALIDATE_EMAIL fails with internationalized domain name addresses containing >1 -).
ftp
  • Fixed bug #60183 (out of sync ftp responses).
gd
  • Fixed bug #60160 (imagefill() doesn't work correctly for small images).
intl
  • Fixed bug #61487 (Incorrent bounds checking in grapheme_strpos).
  • Fixed bug #60192 (SegFault when Collator not constructed properly).
  • Fixed memory leak in several Intl locale functions.
json
  • Fixed bug #55543 (json_encode() with JSON_NUMERIC_CHECK fails on objects with numeric string properties).
mbstring
  • Fixed possible crash in mb_ereg_search_init() using empty pattern.
ms sql
  • Fixed bug #60267 (Compile failure with freetds 0.91).
mysql
  • Fixed bug #55550 (mysql.trace_mode miscounts result sets).
mysqli extension
  • Fixed bug #55859 (mysqli->stat property access gives error).
  • Fixed bug #55582 (mysqli_num_rows() returns always 0 for unbuffered, when mysqlnd is used).
  • Fixed bug #55703 (PHP crash when calling mysqli_fetch_fields).
  • mysqlnd
  • Fixed bug #55609 (mysqlnd cannot be built shared).
  • Fixed bug #55067 (MySQL doesn't support compression - wrong config option).
nsapi sapi
  • Don't set $_SERVER['HTTPS'] on unsecure connection (bug #55403).
openssl
  • Fixed bug #60279 (Fixed NULL pointer dereference in stream_socket_enable_crypto, case when ssl_handle of session_stream is not initialized.)
  • Fix segfault with older versions of OpenSSL.
oracle database extension (oci8)
  • Fixed bug #59985 (show normal warning text for OCI_NO_DATA).
  • Increased maximum Oracle error message buffer length for new 11.2.0.3 size.
  • Improve internal initalization failure error messages.
  • PDO
  • Fixed bug #55776 (PDORow to session bug).
pdo firebird
  • Fixed bug #48877 ("bindValue" and "bindParam" do not work for PDO Firebird).
  • Fixed bug #47415 .
  • Fixed bug #53280 (PDO_Firebird segfaults if query column count less than param count).
pdo mysql driver
  • Fixed bug #60155 (pdo_mysql.default_socket ignored).
  • Fixed bug #55870 (PDO ignores all SSL parameters when used with mysql native driver).
  • Fixed bug #54158 (MYSQLND+PDO MySQL requires #define MYSQL_OPT_LOCAL_INFILE).
pdo oci driver
  • Fixed bug #55768 (PDO_OCI can't resume Oracle session after it's been killed).
phar
  • Fixed bug #60261 (NULL pointer dereference in phar).
  • Fixed bug #60164 (Stubs of a specific length break phar_open_from_fp scanning for __HALT_COMPILER).
  • Fixed bug #53872 (internal corruption of phar).
  • Fixed bug #52013 (Unable to decompress files in a compressed phar).
php-fpm sapi
  • Dropped restriction of not setting the same value multiple times, the last one holds.
  • Added .phar to default authorized extensions.
  • Fixed bug #60659 (FPM does not clear auth_user on request accept).
  • Fixed bug #60629 (memory corruption when web server closed the fcgi fd).
  • Enhance error log when the primary script can't be open. FR #60199.
  • Fixed bug #60179 (php_flag and php_value does not work properly).
  • Fixed bug #55577 (status.html does not install).
  • Fixed bug #55533 (The -d parameter doesn't work).
  • Fixed bug #55526 (Heartbeat causes a lot of unnecessary events).
  • Fixed bug #55486 (status show BIG processes number).
  • Enhanced security by limiting access to user defined extensions. FR #55181.
  • Added process.max to control the number of process FPM can fork. FR #55166.
  • Implemented FR #54577 (Enhanced status page with full status and details about each processes. Also provide a web page (status.html) for real-time FPM status.
  • Lowered default value for Process Manager. FR #54098.
  • Implemented FR #52569 (Add the "ondemand" process-manager to allow zero children).
  • Added partial syslog support (on error_log only). FR #52052.
postgres
  • Fixed bug #60244 (pg_fetch_* functions do not validate that row param is >0).
reflection
  • Fixed bug #60367 (Reflection and Late Static Binding).
session
  • Fixed bug #55267 (session_regenerate_id fails after header sent).
simplexml
  • Reverted the SimpleXML->query() behaviour to returning empty arrays instead of false when no nodes are found as it was since 5.3.3 (bug #48601).
  • SOAP
  • Fixed bug #54911 (Access to a undefined member in inherit SoapClient may cause Segmentation Fault).
  • Fixed bug #48216 (PHP Fatal error: SOAP-ERROR: Parsing WSDL: Extra content at the end of the doc, when server uses chunked transfer encoding with spaces after chunk size).
  • Fixed bug #44686 (SOAP-ERROR: Parsing WSDL with references).
sockets
  • Fixed bug #60048 (sa_len a #define on IRIX).
spl
  • Fixed bug #60082 (Crash in ArrayObject() when using recursive references).
  • Fixed bug #55807 (Wrong value for splFileObject::SKIP_EMPTY).
  • Fixed bug #54304 (RegexIterator::accept() doesn't work with scalar values).
streams
  • Fixed bug #60455 (stream_get_line misbehaves if EOF is not detected together with the last read).
tidy
  • Fixed bug #54682 (Tidy::diagnose() NULL pointer dereference).
xsl
  • Added xsl.security_prefs ini option to define forbidden operations within XSLT stylesheets, default is not to enable write operations. This option won't be in 5.4, since there's a new method. Fixes Bug #54446.
To Top