PHP Release 5.6.11


PHP 5.6.11 Release Announcement

The PHP development team announces the immediate availability of PHP 5.6.11. Five security-related issues in PHP were fixed in this release, including CVE-2015-3152. All PHP 5.6 users are encouraged to upgrade to this version.

For source downloads of PHP 5.6.11 please visit our downloads page, Windows binaries can be found on windows.php.net/download/. The list of changes is recorded in the ChangeLog.

Source Code
PHP 5.6.11 (tar.bz2)
SHA256: bd6b260816764c267244749ead07482120dbf8d1920ebbbb0dcb2aa411033866
PHP 5.6.11 (tar.gz)
SHA256: 85916b46c0d1f2a5315c84fb2773293f4084c3676ba4ed420d0432cbb60ff9d8
PHP 5.6.11 (tar.xz)
SHA256: 3f97dbb1c646b90e1ef638defabe429ef036f903b5baa1c34769d3de4fe62bd4
Change Logs
core
  • Fixed bug #69768 (escapeshell*() doesn't cater to !).
  • Fixed bug #69703 (Use __builtin_clzl on PowerPC).
  • Fixed bug #69732 (can induce segmentation fault with basic php code).
  • Fixed bug #69642 (Windows 10 reported as Windows 8).
  • Fixed bug #69551 (parse_ini_file() and parse_ini_string() segmentation fault).
  • Fixed bug #69781 (phpinfo() reports Professional Editions of Windows 7/8/8.1/10 as "Business").
  • Fixed bug #69740 (finally in generator (yield) swallows exception in iteration).
  • Fixed bug #69835 (phpinfo() does not report many Windows SKUs).
  • Fixed bug #69892 (Different arrays compare indentical due to integer key truncation).
  • Fixed bug #69874 (Can't set empty additional_headers for mail()), regression from fix to bug #68776.
gd
  • Fixed bug #61221 (imagegammacorrect function loses alpha channel).
gmp
  • Fixed bug #69803 (gmp_random_range() modifies second parameter if GMP number).
mysqlnd
  • Fixed bug #69669 (mysqlnd is vulnerable to BACKRONYM). (CVE-2015-3152)
pcre
  • Fixed Bug #53823 (preg_replace: * qualifier on unicode replace garbles the string).
  • Fixed bug #69864 (Segfault in preg_replace_callback)
pdo_pgsql
  • Fixed bug #69752 (PDOStatement::execute() leaks memory with DML Statements when closeCuror() is u).
  • Fixed bug #69362 (PDO-pgsql fails to connect if password contains a leading single quote).
  • Fixed bug #69344 (PDO PgSQL Incorrect binding numeric array with gaps).
phar
  • Fixed bug #69958 (Segfault in Phar::convertToData on invalid file). (CVE-2015-5589)
  • Fixed bug #69923 (Buffer overflow and stack smashing error in phar_fix_filepath). (CVE-2015-5590)
simplexml
  • Refactored the fix for bug #66084 (simplexml_load_string() mangles empty node name).
spl
  • Fixed bug #69737 (Segfault when SplMinHeap::compare produces fatal error).
  • Fixed bug #67805 (SplFileObject setMaxLineLength). .
  • Fixed bug #69970 (Use-after-free vulnerability in spl_recursive_it_move_forward_ex()).
sqlite3
  • Fixed bug #69972 (Use-after-free vulnerability in sqlite3SafetyCheckSickOrOk()).
To Top