PHP Release 5.6.5


PHP 5.6.5 Release Announcement

The PHP development team announces the immediate availability of PHP 5.6.5. This release fixes several bugs as well as CVE-2015-0231, CVE-2014-9427 and CVE-2015-0232. All PHP 5.6 users are encouraged to upgrade to this version.

For source downloads of PHP 5.6.5 please visit our downloads page, Windows binaries can be found on windows.php.net/download/. The list of changes is recorded in the ChangeLog.

Source Code
PHP 5.6.5 (tar.bz2)
SHA256: adab4c0775512a5ca0ae74e08efdc941d92529b75283e0f44d3f53822cdfd06d
PHP 5.6.5 (tar.gz)
SHA256: f67c480bcf2f6f703ec8d8a772540f4a518f766b08d634d7a919402c13a636cf
PHP 5.6.5 (tar.xz)
SHA256: c5ef4abaef8c1ea66dcfd5a075a2f357b666aff5c5b686fca7c78c1cfd64e996
Change Logs
core
  • Upgraded crypt_blowfish to version 1.3.
  • Fixed bug #60704 bug with some files path).
  • Fixed bug #65419 (Inside trait, self::class != __CLASS__).
  • Fixed bug #68536 (pack for 64bits integer is broken on bigendian).
  • Fixed bug #55541 (errors spawn MessageBox, which blocks test automation).
  • Fixed bug #68297 (Application Popup provides too few information).
  • Fixed bug #65769 (localeconv() broken in TS builds).
  • Fixed bug #65230 (setting locale randomly broken).
  • Fixed bug #66764 (configure doesn't define EXPANDED_DATADIR / PHP_DATADIR correctly).
  • Fixed bug #68583 (Crash in timeout thread).
  • Fixed bug #65576 (Constructor from trait conflicts with inherited constructor).
  • Fixed bug #68676 (Explicit Double Free). (CVE-2014-9425)
  • Fixed bug #68710 (Use After Free Vulnerability in PHP's unserialize()). (CVE-2015-0231)
cgi
  • Fixed bug #68618 (out of bounds read crashes php-cgi). (CVE-2014-9427)
cli server
  • Fixed bug #68745 (Invalid HTTP requests make web server segfault).
curl
  • Fixed bug #67643 (curl_multi_getcontent returns '' when CURLOPT_RETURNTRANSFER isn't set).
date
  • Implemented FR #68268 (DatePeriod: Getter for start date, end date and interval).
exif
  • Fixed bug #68799: Free called on uninitialized pointer. (CVE-2015-0232)
fileinfo
  • Fixed bug #68398 (msooxml matches too many archives).
  • Fixed bug #68665 (invalid free in libmagic).
  • Fixed bug #68671 (incorrect expression in libmagic).
  • Removed readelf.c and related code from libmagic sources
  • Fixed bug #68735 (fileinfo out-of-bounds memory access). (CVE-2014-9652)
fpm
  • Fixed request #68526 (Implement POSIX Access Control List for UDS).
  • Fixed bug #68751 (listen.allowed_clients is broken).
gd
  • Fixed bug #68601 (buffer read overflow in gd_gif_in.c). (CVE-2014-9709)
  • Fixed request #68656 (Report gd library version).
mbstring
  • Fixed bug #68504 (--with-libmbfl configure option not present on Windows).
opcache
  • Fixed bug #68644 (strlen incorrect : mbstring + func_overload=2 +UTF-8 + Opcache).
  • Fixed bug #67111 (Memory leak when using "continue 2" inside two foreach loops).
openssl
  • Improved handling of OPENSSL_KEYTYPE_EC keys.
pcntl
  • Fixed bug #60509 (pcntl_signal doesn't decrease ref-count of old handler when setting SIG_DFL).
pcre
  • Fixed bug #66679 (Alignment Bug in PCRE 8.34 upstream).
pgsql
  • Fixed bug #68697 (lo_export return -1 on failure).
pdo
  • Fixed bug #68371 (PDO#getAttribute() cannot be called with platform-specifi attribute names).
pdo_mysql
  • Fixed bug #68424 (Add new PDO mysql connection attr to control multi statements option).
spl
  • Fixed bug #66405 (RecursiveDirectoryIterator::CURRENT_AS_PATHNAME breaks the RecursiveIterator).
  • Fixed bug #68479 (Added escape parameter to SplFileObject::fputcsv).
sqlite
  • Fixed bug #68120 (Update bundled libsqlite to 3.8.7.2).
streams
  • Fixed bug #68532 (convert.base64-encode omits padding bytes).
To Top