Version 5.6

PHP 5.6.40
Released 10 Jan, 2019
gd
  • Fixed bug #77269 (efree() on uninitialized Heap data in imagescale leads to use-after-free).
  • Fixed bug #77270 (imagecolormatch Out Of Bounds Write on Heap).
mbstring
  • Fixed bug #77370 (Buffer overflow on mb regex functions - fetch_token).
  • Fixed bug #77371 (heap buffer overflow in mb regex functions
  • compile_string_node).
  • Fixed bug #77381 (heap buffer overflow in multibyte match_at).
  • Fixed bug #77382 (heap buffer overflow due to incorrect length in expand_case_fold_string).
  • Fixed bug #77385 (buffer overflow in fetch_token).
  • Fixed bug #77394 (Buffer overflow in multibyte case folding - unicode).
  • Fixed bug #77418 (Heap overflow in utf32be_mbc_to_code).
phar
  • Fixed bug #77247 (heap buffer overflow in phar_detect_phar_fname_ext).
xmlrpc
  • Fixed bug #77242 (heap out of bounds read in xmlrpc_decode()).
  • Fixed bug #77380 (Global out of bounds read in xmlrpc base64 code).
PHP 5.6.39
Released 06 Dec, 2018
core
  • Fixed bug #77231 (Segfault when using convert.quoted-printable-encode filter).
imap
  • Fixed bug #77020 (null pointer dereference in imap_mail).
  • Fixed bug #77153 (imap_open allows to run arbitrary shell commands via mailbox parameter).
phar
  • Fixed bug #77022 (PharData always creates new files with mode 0666).
  • Fixed bug #77143 (Heap Buffer Overflow (READ: 4) in phar_parse_pharfile).
PHP 5.6.38
Released 13 Sep, 2018
PHP 5.6.37
Released 19 Jul, 2018
exif
  • Fixed bug #76423 (Int Overflow lead to Heap OverFlow in exif_thumbnail_extract of exif.c).
  • Fixed bug #76557 (heap-buffer-overflow (READ of size 48) while reading exif data).
  • Fixed bug #76130 (Heap Buffer Overflow (READ: 1786) in exif_iif_add_value).
win32
  • Fixed bug #76459 (windows linkinfo lacks openbasedir check).
iconv
  • Fixed bug #76249 (stream filter convert.iconv leads to infinite loop on invalid sequence).
ldap
  • Fixed bug #76248 (Malicious LDAP-Server Response causes Crash).
phar
  • Fixed bug #76129 (fix for CVE-2018-5712 may not be complete).
PHP 5.6.36
Released 26 Apr, 2018
PHP 5.6.35
Released 29 Mar, 2018
fpm
  • Fixed bug #75605 (Dumpable FPM child processes allow bypassing opcache access controls).
PHP 5.6.34
Released 01 Mar, 2018
standard
  • Fixed bug #75981 (stack-buffer-overflow while parsing HTTP response).
PHP 5.6.33
Released 04 Jan, 2018
gd
  • Fixed bug #75571 (Potential infinite loop in gdImageCreateFromGifCtx).
phar
  • Fixed bug #74782 (Reflected XSS in .phar 404 page).
PHP 5.6.32
Released 26 Oct, 2017
date
  • Fixed bug #75055 (Out-Of-Bounds Read in timelib_meridian()).
mcrypt
  • Fixed bug #72535 (arcfour encryption stream filter crashes php).
pcre
  • Fixed bug #75207 (applied upstream patch for CVE-2016-1283).
PHP 5.6.31
Released 06 Jul, 2017
core
  • Fixed bug #73807 (Performance problem with processing post request over 2000000 chars).
  • Fixed bug #74111 (Heap buffer overread (READ: 1) finish_nested_data from unserialize).
  • Fixed bug #74603 (PHP INI Parsing Stack Buffer Overflow Vulnerability).
  • Fixed bug #74819 (wddx_deserialize() heap out-of-bound read via php_parse_date()).
gd
  • Fixed bug #74435 (Buffer over-read into uninitialized memory).
mbstring
  • Add oniguruma upstream fix (CVE-2017-9224, CVE-2017-9226, CVE-2017-9227, CVE-2017-9228, CVE-2017-9229)
openssl
  • Fixed bug #74651 (negative-size-param (-1) in memcpy in zif_openssl_seal()).
pcre
  • Fixed bug #74087 (Segmentation fault in PHP7.1.1(compiled using the bundled PCRE library)).
wddx
  • Fixed bug #74145 (wddx parsing empty boolean tag leads to SIGSEGV).
PHP 5.6.30
Released 19 Jan, 2017
exif
  • Fixed bug #73737 (FPE when parsing a tag format).
gd
  • Fixed bug #73549 (Use after free when stream is passed to imagepng).
  • Fixed bug #73868 (DOS vulnerability in gdImageCreateFromGd2Ctx()).
  • Fixed bug #73869 (Signed Integer Overflow gd_io.c).
intl
  • Fixed bug #68447 (grapheme_extract take an extra trailing character).
phar
  • Fixed bug #73764 (Crash while loading hostile phar archive).
  • Fixed bug #73768 (Memory corruption when loading hostile phar).
  • Fixed bug #73773 (Seg fault when loading hostile phar).
sqlite3
  • Reverted fix for bug #73530 (Unsetting result set may reset other result set).
standard
  • Fixed bug #70213 (Unserialize context shared on double class lookup).
  • Fixed bug #73825 (Heap out of bounds read on unserialize in finish_nested_data()).
PHP 5.6.29
Released 08 Dec, 2016
mbstring
  • Fixed bug #73505 (string length overflow in mbfl_memory_device_output function).
mysqlnd
  • Fixed bug #64526 (Add missing mysqlnd.* parameters to php.ini-*).
opcache
  • Fixed bug #73402 (Opcache segfault when using class constant to call a method).
  • Fixed bug #69090
  • OpenSSL
  • Fixed bug #72776 (Invalid parameter in memcpy function trough openssl_pbkdf2).
postgres
  • Fixed bug #73498 (Incorrect SQL generated for pg_copy_to()).
soap
  • Fixed bug #73452 (Segfault (Regression for #69152)).
sqlite3
  • Fixed bug #73530 (Unsetting result set may reset other result set).
standard
  • Fixed bug #73297 (HTTP stream wrapper should ignore HTTP 100 Continue).
wddx
  • Fixed bug #73631 (Memory leak due to invalid wddx stack processing). .
PHP 5.6.28
Released 10 Nov, 2016
core
  • Fixed bug #73337 (try/catch not working with two exceptions inside a same operation).
bz2
  • Fixed bug #73356 (crash in bzcompress function).
  • Fixed bug #73213 (Integer overflow in imageline() with antialiasing).
  • Fixed bug #73272 (imagescale() is not affected by, but affects imagesetinterpolation()).
  • Fixed bug #73279 (Integer overflow in gdImageScaleBilinearPalette()).
  • Fixed bug #73280 (Stack Buffer Overflow in GD dynamicGetbuf).
  • Fixed bug #72482 (Illegal write/read access caused by gdImageAALine overflow).
  • Fixed bug #72696 (imagefilltoborder stackoverflow on truecolor images).
imap
  • Fixed bug #73418 (Integer Overflow in "_php_imap_mail" leads Heap Overflow).
spl
  • Fixed bug #73144 (Use-after-free in ArrayObject Deserialization).
soap
  • Fixed bug #73037 (SoapServer reports Bad Request when gzipped).
sqlite3
  • Fixed bug #73333 (2147483647 is fetched as string).
standard
  • Fixed bug #73203 (passing additional_parameters causes mail to fail).
  • Fixed bug #73188 (use after free in userspace streams).
  • Fixed bug #73192 (parse_url return wrong hostname).
wddx
  • Fixed bug #73331 (NULL Pointer Dereference in WDDX Packet Deserialization with PDORow).
PHP 5.6.27
Released 13 Oct, 2016
core
  • Fixed bug #73025 (Heap Buffer Overflow in virtual_popen of zend_virtual_cwd.c).
  • Fixed bug #73058 (crypt broken when salt is 'too' long).
  • Fixed bug #72703 (Out of bounds global memory read in BF_crypt triggered by password_verify).
  • Fixed bug #73189 (Memcpy negative size parameter php_resolve_path).
  • Fixed bug #73147 (Use After Free in unserialize()).
bcmath
  • Fixed bug #73190 (memcpy negative parameter _bc_new_num_ex).
dom
  • Fixed bug #73150 (missing NULL check in dom_document_save_html).
ereg
  • Fixed bug #73284 (heap overflow in php_ereg_replace function).
filter
  • Fixed bug #72972 (Bad filter for the flags FILTER_FLAG_NO_RES_RANGE and FILTER_FLAG_NO_PRIV_RANGE).
  • Fixed bug #67167 (Wrong return value from FILTER_VALIDATE_BOOLEAN, FILTER_NULL_ON_FAILURE).
  • Fixed bug #73054 (default option ignored when object passed to int filter).
gd
  • Fixed bug #67325 (imagetruecolortopalette: white is duplicated in palette).
  • Fixed bug #50194 (imagettftext broken on transparent background w/o alphablending).
  • Fixed bug #73003 (Integer Overflow in gdImageWebpCtx of gd_webp.c).
  • Fixed bug #53504 (imagettfbbox gives incorrect values for bounding box).
  • Fixed bug #73157 (imagegd2() ignores 3rd param if 4 are given).
  • Fixed bug #73155 (imagegd2() writes wrong chunk sizes on boundaries).
  • Fixed bug #73159 (imagegd2(): unrecognized formats may result in corrupted files).
  • Fixed bug #73161 (imagecreatefromgd2() may leak memory).
intl
  • Fixed bug #73218 (add mitigation for ICU int overflow).
imap
  • Fixed bug #73208 (integer overflow in imap_8bit caused heap corruption).
mbstring
  • Fixed bug #72994 (mbc_to_code() out of bounds read).
  • Fixed bug #66964 (mb_convert_variables() cannot detect recursion).
  • Fixed bug #72992 (mbstring.internal_encoding doesn't inherit default_charset).
  • Fixed bug #73082 (string length overflow in mb_encode_* function).
pcre
  • Fixed bug #73174 (heap overflow in php_pcre_replace_impl).
opcache
  • Fixed bug #72590 (Opcache restart with kill_all_lockers does not work). (Keyur)
openssl
  • Fixed bug #73072 (Invalid path SNI_server_certs causes segfault).
  • Fixed bug #73275 (crash in openssl_encrypt function).
  • Fixed bug #73276 (crash in openssl_random_pseudo_bytes function).
session
  • Fixed bug #68015 (Session does not report invalid uid for files save handler).
  • Fixed bug #73100 (session_destroy null dereference in ps_files_path_create).
simplexml
  • Fixed bug #73293 (NULL pointer dereference in SimpleXMLElement::asXML()).
spl
  • Fixed bug #73073 (CachingIterator null dereference when convert to string).
standard
  • Fixed bug #73240 (Write out of bounds at number_format).
  • Fixed bug #73017 (memory corruption in wordwrap function).
stream
  • Fixed bug #73069 (readfile() mangles files larger than 2G).
zip
  • Fixed bug #70752 (Depacking with wrong password leaves 0 length files).
PHP 5.6.26
Released 15 Sep, 2016
core
  • Fixed bug #72907 (null pointer deref, segfault in gc_remove_zval_from_buffer (zend_gc.c:260)).
dba
  • Fixed bug #71514 (Bad dba_replace condition because of wrong API usage).
  • Fixed bug #70825 (Cannot fetch multiple values with group in ini file).
exif
  • Fixed bug #72926 (Uninitialized Thumbail Data Leads To Memory Leakage in exif_process_IFD_in_TIFF).
ftp
  • Fixed bug #70195 (Cannot upload file using ftp_put to FTPES with require_ssl_reuse).
gd
  • Fixed bug #66005 (imagecopy does not support 1bit transparency on truecolor images).
  • Fixed bug #72913 (imagecopy() loses single-color transparency on palette images).
  • Fixed bug #68716 (possible resource leaks in _php_image_convert()).
intl
  • Fixed bug #73007 (add locale length check).
json
  • Fixed bug #72787 (json_decode reads out of bounds).
mbstring
  • Fixed bug #66797 (mb_substr only takes 32-bit signed integer).
  • Fixed bug #72910 (Out of bounds heap read in mbc_to_code() / triggered by mb_ereg_match()).
mssql
  • Fixed bug #72039 (Use of uninitialised value on mssql_guid_string).
mysqlnd
  • Fixed bug #72293 (Heap overflow in mysqlnd related to BIT fields).
phar
  • Fixed bug #72928 (Out of bound when verify signature of zip phar in phar_parse_zipfile).
  • Fixed bug #73035 (Out of bound when verify signature of tar phar in phar_parse_tarfile).
pdo
  • Fixed bug #60665 (call to empty() on NULL result using PDO::FETCH_LAZY returns false).
pdo_pgsql
  • Implemented FR #72633 (Postgres PDO lastInsertId() should work without specifying a sequence).
  • Fixed bug #72759 (Regression in pgo_pgsql).
spl
  • Fixed bug #73029 (Missing type check when unserializing SplArray).
standard
  • Fixed bug #72823 (strtr out-of-bound access).
  • Fixed bug #72278 (getimagesize returning FALSE on valid jpg).
  • Fixed bug #65550 (get_browser() incorrectly parses entries with "+" sign).
  • Fixed bug #71882 (Negative ftruncate() on php://memory exhausts memory).
  • Fixed bug #73011 (integer overflow in fgets cause heap corruption).
  • Fixed bug #73017 (memory corruption in wordwrap function).
  • Fixed bug #73045 (integer overflow in fgetcsv caused heap corruption).
  • Fixed bug #73052 (Memory Corruption in During Deserialized-object Destruction)
streams
  • Fixed bug #72853 (stream_set_blocking doesn't work).
wddx
  • Fixed bug #72860 (wddx_deserialize use-after-free).
  • Fixed bug #73065 (Out-Of-Bounds Read in php_wddx_push_element).
xml
  • Fixed bug #72085 (SEGV on unknown address zif_xml_parse).
  • Fixed bug #72927 (integer overflow in xml_utf8_encode).
zip
  • Fixed bug #68302 (impossible to compile php with zip support).
PHP 5.6.25
Released 18 Aug, 2016
bz2
  • Fixed bug #72837 (integer overflow in bzdecompress caused heap corruption).
core
  • Fixed bug #70436 (Use After Free Vulnerability in unserialize()).
  • Fixed bug #72024 (microtime() leaks memory).
  • Fixed bug #72581 (previous property undefined in Exception after deserialization).
  • Implemented FR #72614 (Support "nmake test" on building extensions by phpize).
  • Fixed bug #72641 (phpize (on Windows) ignores PHP_PREFIX).
  • Fixed bug #72663 (Create an Unexpected Object and Don't Invoke __wakeup() in Deserialization).
  • Fixed bug #72681 (PHP Session Data Injection Vulnerability).
  • Fixed URL rewriter partially. It would not rewrite '//example.com/' URL unconditionally. Only requested host(HTTP_HOST) is rewritten.
calendar
  • Fixed bug #67976 (cal_days_month() fails for final month of the French calendar).
  • Fixed bug #71894 (AddressSanitizer: global-buffer-overflow in zif_cal_from_jd).
curl
  • Fixed bug #71144 (Segmentation fault when using cURL with ZTS).
  • Fixed bug #71929 (Certification information (CERTINFO) data parsing error).
  • Fixed bug #72807 (integer overflow in curl_escape caused heap corruption).
dom
  • Fixed bug #66502 (DOM document dangling reference).
ereg
  • Fixed bug #72838 (Integer overflow lead to heap corruption in sql_regcase).
exif
  • Fixed bug #72627 (Memory Leakage In exif_process_IFD_in_TIFF).
  • Fixed bug #72735 (Samsung picture thumb not read (zero size)).
filter
  • Fixed bug #71745 (FILTER_FLAG_NO_RES_RANGE does not cover whole 127.0.0.0/8 range).
fpm
  • Fixed bug #72575 (using --allow-to-run-as-root should ignore missing user).
gd
  • Fixed bug #43828 (broken transparency of imagearc for truecolor in blendingmode).
  • Fixed bug #66555 (Always false condition in ext/gd/libgd/gdkanji.c).
  • Fixed bug #68712 (suspicious if-else statements).
  • Fixed bug #70315 (500 Server Error but page is fully rendered).
  • Fixed bug #72596 (imagetypes function won't advertise WEBP support).
  • Fixed bug #72604 (imagearc() ignores thickness for full arcs).
  • Fixed bug #72697 (select_colors write out-of-bounds).
  • Fixed bug #72709 (imagesetstyle() causes OOB read for empty $styles).
  • Fixed bug #72730 (imagegammacorrect allows arbitrary write access).
  • Fixed bug #72494 (imagecropauto out-of-bounds access).
intl
  • Partially fixed #72506 (idn_to_ascii for UTS #46 incorrect for long domain names).
mbstring
  • Fixed bug #72691 (mb_ereg_search raises a warning if a match zero-width).
  • Fixed bug #72693 (mb_ereg_search increments search position when a match zero-width).
  • Fixed bug #72694 (mb_ereg_search_setpos does not accept a string's last position).
  • Fixed bug #72710 (`mb_ereg` causes buffer overflow on regexp compile error).
oci8
  • Fixed invalid handle error with Implicit Result Sets.
pcre
  • Fixed bug #72688 (preg_match missing group names in matches).
pdo_pgsql
  • Fixed bug #70313 (PDO statement fails to throw exception).
reflection
  • Fixed bug #72222 (ReflectionClass::export doesn't handle array constants).
snmp
  • Fixed bug #72708 (php_snmp_parse_oid integer overflow in memory allocation).
standard
  • Fixed bug #72330 (CSV fields incorrectly split if escape char followed by UTF chars).
  • Fixed bug #72836 (integer overflow in base64_decode).
  • Fixed bug #72848 (integer overflow in quoted_printable_encode).
  • Fixed bug #72849 (integer overflow in urlencode).
  • Fixed bug #72850 (integer overflow in php_uuencode).
streams
  • Fixed bug #41021 (Problems with the ftps wrapper).
  • Fixed bug #54431 (opendir() does not work with ftps:// wrapper).
  • Fixed bug #72667 (opendir() with ftp:// attempts to open data stream for non-existent directories).
  • Fixed bug #72764 (ftps:// opendir wrapper data channel encryption fails with IIS FTP 7.5, 8.5).
  • Fixed bug #72771 (ftps:// wrapper is vulnerable to protocol downgrade attack).
spl
  • Fixed bug #72122 (IteratorIterator breaks '@' error suppression).
  • Fixed bug #72646 (SplFileObject::getCsvControl does not return the escape character).
  • Fixed bug #72684 (AppendIterator segfault with closed generator).
sqlite3
  • Implemented FR #72653 (SQLite should allow opening with empty filename).
wddx
  • Fixed bug #72142 (WDDX Packet Injection Vulnerability in wddx_serialize_value()).
  • Fixed bug #72749 (wddx_deserialize allows illegal memory access)
  • Fixed bug #72750 (wddx_deserialize null dereference).
  • Fixed bug #72790 (wddx_deserialize null dereference with invalid xml).
  • Fixed bug #72799 (wddx_deserialize null dereference in php_wddx_pop_element).
PHP 5.6.24
Released 21 Jul, 2016
core
  • Fixed bug #71936 (Segmentation fault destroying HTTP_RAW_POST_DATA).
  • Fixed bug #72496 (Cannot declare public method with signature incompatible with parent private method).
  • Fixed bug #72138 (Integer Overflow in Length of String-typed ZVAL).
  • Fixed bug #72513 (Stack-based buffer overflow vulnerability in virtual_file_ex).
  • Fixed bug #72562 (Use After Free in unserialize() with Unexpected Session Deserialization).
  • Fixed bug #72573 (HTTP_PROXY is improperly trusted by some PHP libraries and applications). (CVE-2016-5385)
bz2
  • Fixed bug #72447 (Type Confusion in php_bz2_filter_create()). .
  • Fixed bug #72613 (Inadequate error handling in bzread()).
date
  • Fixed bug #66836 (DateTime::createFromFormat 'U' with pre 1970 dates fails parsing).
exif
  • Fixed bug #50845 (exif_read_data() returns corrupted exif headers).
  • Fixed bug #72603 (Out of bound read in exif_process_IFD_in_MAKERNOTE).
  • Fixed bug #72618 (NULL Pointer Dereference in exif_process_user_comment).
gd
  • Fixed bug #43475 (Thick styled lines have scrambled patterns).
  • Fixed bug #53640 (XBM images require width to be multiple of 8).
  • Fixed bug #64641 (imagefilledpolygon doesn't draw horizontal line).
  • Fixed bug #72512 (gdImageTrueColorToPaletteBody allows arbitrary write/read access).
  • Fixed bug #72519 (imagegif/output out-of-bounds access).
  • Fixed bug #72558 (Integer overflow error within _gdContributionsAlloc()). (CVE-2016-6207)
intl
  • Fixed bug #72533 (locale_accept_from_http out-of-bounds access).
openssl
  • Fixed bug #71915 (openssl_random_pseudo_bytes is not fork-safe).
  • Fixed bug #72336 (openssl_pkey_new does not fail for invalid DSA params).
snmp
  • Fixed bug #72479 (Use After Free Vulnerability in SNMP with GC and unserialize()).
spl
  • Fixed bug #55701 (GlobIterator throws LogicException).
sqlite3
  • Fixed bug #70628 (Clearing bindings on an SQLite3 statement doesn't work).
streams
  • Fixed bug #72439 (Stream socket with remote address leads to a segmentation fault).
xmlrpc
  • Fixed bug #72606 (heap-buffer-overflow (write) simplestring_addn simplestring.c).
zip
  • Fixed bug #72520 (Stack-based buffer overflow vulnerability in php_stream_zip_opener).
PHP 5.6.23
Released 23 Jun, 2016
core
  • Fixed bug #72268 (Integer Overflow in nl2br()).
  • Fixed bug #72275 (Integer Overflow in json_encode()/json_decode()/ json_utf8_to_utf16()).
  • Fixed bug #72400 (Integer Overflow in addcslashes/addslashes).
  • Fixed bug #72403 (Integer Overflow in Length of String-typed ZVAL).
date
  • Fixed bug #63740 (strtotime seems to use both sunday and monday as start of week).
gd
  • Fixed bug #66387 (Stack overflow with imagefilltoborder). (CVE-2015-8874)
  • Fixed bug #72298 (pass2_no_dither out-of-bounds access).
  • Fixed bug #72337 (invalid dimensions can lead to crash).
  • Fixed bug #72339 (Integer Overflow in _gd2GetHeader() resulting in heap overflow). (CVE-2016-5766)
  • Fixed bug #72407 (NULL Pointer Dereference at _gdScaleVert).
  • Fixed bug #72446 (Integer Overflow in gdImagePaletteToTrueColor() resulting in heap overflow). (CVE-2016-5767)
intl
  • Fixed bug #70484 (selectordinal doesn't work with named parameters).
mbstring
  • Fixed bug #72402 (_php_mb_regex_ereg_replace_exec - double free). (CVE-2016-5768)
mcrypt
  • Fixed bug #72455 (Heap Overflow due to integer overflows). (CVE-2016-5769)
openssl
  • Fixed bug #72140 (segfault after calling ERR_free_strings()).
phar
  • Fixed bug #72321 (invalid free in phar_extract_file()).
spl
  • Fixed bug #72262 (int/size_t confusion in SplFileObject::fread). (CVE-2016-5770)
  • Fixed bug #72433 (Use After Free Vulnerability in PHP's GC algorithm and unserialize). (CVE-2016-5771)
wddx
  • Fixed bug #72340 (Double Free Courruption in wddx_deserialize). (CVE-2016-5772)
zip
  • Fixed bug #72434 (ZipArchive class Use After Free Vulnerability in PHP's GC algorithm and unserialize). (CVE-2016-5773)
PHP 5.6.22
Released 26 May, 2016
core
  • Fixed bug #72172 (zend_hex_strtod should not use strlen).
  • Fixed bug #72114 (Integer underflow / arbitrary null write in fread/gzread). (CVE-2016-5096)
  • Fixed bug #72135 (Integer Overflow in php_html_entities). (CVE-2016-5094)
gd
  • Fixed bug #72227 (imagescale out-of-bounds read). (CVE-2013-7456)
  • Intl
  • Fixed bug #64524 (Add intl.use_exceptions to php.ini-*).
  • Fixed bug #72241 (get_icu_value_internal out-of-bounds read). (CVE-2016-5093)
postgres
  • Fixed bug #72151 (mysqli_fetch_object changed behaviour).
PHP 5.6.21
Released 28 Apr, 2016
core
  • Fixed bug #69537 (__debugInfo with empty string for key gives error).
  • Fixed bug #71841 (EG(error_zval) is not handled well).
bcmath
  • Fixed bug #72093 (bcpowmod accepts negative scale and corrupts _one_ definition).
curl
  • Fixed bug #71831 (CURLOPT_NOPROXY applied as long instead of string).
date
  • Fixed bug #71889 (DateInterval::format Segmentation fault).
exif
  • Fixed bug #72094 (Out of bounds heap read access in exif header processing).
gd
  • Fixed bug #71952 (Corruption inside imageaffinematrixget).
  • Fixed bug #71912 (libgd: signedness vulnerability). (CVE-2016-3074)
intl
  • Fixed bug #72061 (Out-of-bounds reads in zif_grapheme_stripos with negative offset).
oci8
  • Fixed bug #71422 (Fix ORA-01438: value larger than specified precision allowed for this column).
odbc
  • Fixed bug #63171 (Script hangs after max_execution_time).
opcache
  • Fixed bug #71843 (null ptr deref ZEND_RETURN_SPEC_CONST_HANDLER).
pdo
  • Fixed bug #52098 (Own PDOStatement implementation ignore __call()).
  • Fixed bug #71447 (Quotes inside comments not properly handled).
postgres
  • Fixed bug #71820 (pg_fetch_object binds parameters before call constructor).
spl
  • Fixed bug #67582 (Cloned SplObjectStorage with overwritten getHash fails offsetExists()).
standard
  • Fixed bug #71840 (Unserialize accepts wrongly data).
  • Fixed bug #67512 (php_crypt() crashes if crypt_r() does not exist or _REENTRANT is not defined).
xml
  • Fixed bug #72099 (xml_parse_into_struct segmentation fault).
PHP 5.6.20
Released 31 Mar, 2016
cli server
  • Fixed bug #69953 (Support MKCALENDAR request method).
core
  • Fixed bug #71596 (Segmentation fault on ZTS with date function (setlocale)).
curl
  • Fixed bug #71694 (Support constant CURLM_ADDED_ALREADY).
date
  • Fixed bug #71635 (DatePeriod::getEndDate segfault).
fileinfo
  • Fixed bug #71527 (Buffer over-write in finfo_open with malformed magic file). (CVE-2015-8865)
mbstring
  • Fixed bug #71906 (AddressSanitizer: negative-size-param (-1) in mbfl_strcut). (CVE-2016-4073)
odbc
  • Fixed bug #47803, #69526 (Executing prepared statements is succesfull only for the first two statements).
  • Fixed bug #71860 (Invalid memory write in phar on filename with \0 in name). (CVE-2016-4072)
pdo_dblib
  • Fixed bug #54648 (PDO::MSSQL forces format of datetime fields).
phar
  • Fixed bug #71625 (Crash in php7.dll with bad phar filename).
  • Fixed bug #71504 (Parsing of tar file with duplicate filenames causes memory leak).
snmp
  • Fixed bug #71704 (php_snmp_error() Format String Vulnerability). (CVE-2016-4071)
standard
  • Fixed bug #71798 (Integer Overflow in php_raw_url_encode). (CVE-2016-4070)
PHP 5.6.19
Released 03 Mar, 2016
cli server
  • Fixed bug #71559 (Built-in HTTP server, we can download file in web by bug).
curl
  • Fixed bug #71523 (Copied handle with new option CURLOPT_HTTPHEADER crashes while curl_multi_exec).
date
  • Fixed bug #68078 (Datetime comparisons ignore microseconds).
  • Fixed bug #71525 (Calls to date_modify will mutate timelib_rel_time, causing date_date_set issues).
fileinfo
  • Fixed bug #71434 (finfo throws notice for specific python file).
fpm
  • Fixed bug #62172 (FPM not working with Apache httpd 2.4 balancer/fcgi setup).
opcache
  • Fixed bug #71584 (Possible use-after-free of ZCG(cwd) in Zend Opcache).
pdo mysql
  • Fixed bug #71569 (#70389 fix causes segmentation fault).
phar
  • Fixed bug #71498 (Out-of-Bound Read in phar_parse_zipfile()).
standard
  • Fixed bug #70720 (strip_tags improper php code parsing).
wddx
  • Fixed bug #71587 (Use-After-Free / Double-Free in WDDX Deserialize).
xsl
  • Fixed bug #71540 (NULL pointer dereference in xsl_ext_function_php()).
zip
  • Fixed bug #71561 (NULL pointer dereference in Zip::ExtractTo).
PHP 5.6.18
Released 04 Feb, 2016
core
  • Fixed bug #71039 (exec functions ignore length but look for NULL termination).
  • Fixed bug #71089 (No check to duplicate zend_extension).
  • Fixed bug #71201 (round() segfault on 64-bit builds).
  • Added support for new HTTP 451 code.
  • Fixed bug #71273 (A wrong ext directory setup in php.ini leads to crash).
  • Fixed bug #71323 (Output of stream_get_meta_data can be falsified by its input).
  • Fixed bug #71459 (Integer overflow in iptcembed()).
apache2handler
  • Fix >2G Content-Length headers in apache2handler.
ftp
  • Implemented FR #55651 (Option to ignore the returned FTP PASV address).
opcache
  • Fixed bug #71127 (Define in auto_prepend_file is overwrite).
  • Fixed bug #71024 (Unable to use PHP 7.0 x64 side-by-side with PHP 5.6 x32 on the same server).
pcre
  • Upgraded bundled PCRE library to 8.38.
phar
  • Fixed bug #71354 (Heap corruption in tar/zip/phar parser). (CVE-2016-4342)
  • Fixed bug #71331 (Uninitialized pointer in phar_make_dirstream()). (CVE-2016-4343)
  • Fixed bug #71391 (NULL Pointer Dereference in phar_tar_setupmetadata()).
  • Fixed bug #71488 (Stack overflow when decompressing tar archives). (CVE-2016-2554)
session
  • Fixed bug #69111 (Crash in SessionHandler::read()).
soap
  • Fixed bug #70979 (crash with bad soap request).
spl
  • Fixed bug #71204 (segfault if clean spl_autoload_funcs while autoloading).
wddx
  • Fixed bug #71335 (Type Confusion in WDDX Packet Deserialization).
PHP 5.6.17
Released 07 Jan, 2016
core
  • Fixed bug #66909 (configure fails utf8_to_mutf7 test).
  • Fixed bug #70958 (Invalid opcode while using ::class as trait method paramater default value).
  • Fixed bug #70957 (self::class can not be resolved with reflection for abstract class).
  • Fixed bug #70944 (try{ } finally{} can create infinite chains of exceptions).
  • Fixed bug #61751 (SAPI build problem on AIX: Undefined symbol: php_register_internal_extensions).
fpm
  • Fixed bug #70755 (fpm_log.c memory leak and buffer overflow).
gd
  • Fixed bug #70976 (Memory Read via gdImageRotateInterpolated Array Index Out of Bounds). (CVE-2016-1903)
mysqlnd
  • Fixed bug #68077 (LOAD DATA LOCAL INFILE / open_basedir restriction).
soap
  • Fixed bug #70900 (SoapClient systematic out of memory error).
standard
  • Fixed bug #70960 (ReflectionFunction for array_unique returns wrong number of parameters).
pdo_firebird
  • Fixed bug #60052 (Integer returned as a 64bit integer on X64_86).
wddx
  • Fixed bug #70661 (Use After Free Vulnerability in WDDX Packet Deserialization).
  • Fixed bug #70741 (Session WDDX Packet Deserialization Type Confusion Vulnerability).
xmlrpc
  • Fixed bug #70728 (Type Confusion Vulnerability in PHP_to_XMLRPC_worker()).
PHP 5.6.16
Released 26 Nov, 2015
core
  • Fixed bug #70828 (php-fpm 5.6 with opcache crashes when referencing a non-existent constant).
  • Fixed bug #70748 (Segfault in ini_lex () at Zend/zend_ini_scanner.l).
mysqlnd
  • Fixed bug #68344 (MySQLi does not provide way to disable peer certificate validation) by introducing MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT connection flag.
oci8
  • Fixed bug #68298 (OCI int overflow).
pdo_dblib
  • Fixed bug #69757 (Segmentation fault on nextRowset).
soap
  • Fixed bug #70875 (Segmentation fault if wsdl has no targetNamespace attribute).
spl
  • Fixed bug #70852 (Segfault getting NULL offset of an ArrayObject).
PHP 5.6.15
Released 29 Oct, 2015
core
  • Fixed bug #70681 (Segfault when binding $this of internal instance method to null).
  • Fixed bug #70685 (Segfault for getClosure() internal method rebind with invalid $this).
date
  • Fixed bug #70619 (DateTimeImmutable segfault).
mcrypt
  • Fixed bug #70625 (mcrypt_encrypt() won't return data when no IV was specified under RC4).
mysqlnd
  • Fixed bug #70384 (mysqli_real_query():Unknown type 245 sent by the server).
  • Fixed bug #70572 segfault in mysqlnd_connect.
opcache
  • Fixed bug #70632 (Third one of segfault in gc_remove_from_buffer).
  • Fixed bug #70631 (Another Segfault in gc_remove_from_buffer()).
  • Fixed bug #70601 (Segfault in gc_remove_from_buffer()).
  • Fixed compatibility with Windows 10 (see also bug #70652).
PHP 5.6.14
Released 01 Oct, 2015
core
  • Fixed bug #70370 (Bundled libtool.m4 doesn't handle FreeBSD 10 when building extensions).
cli server
  • Fixed bug #68291 (404 on urls with '+').
dom
  • Fixed bug #70001 (Assigning to DOMNode::textContent does additional entity encoding).
ldap
  • Fixed bug #70465 (Bug in ldap_search() modifies LDAP_OPT_TIMELIMIT/DEREF's values).
  • Fixed bug #69574 (ldap timeouts not enforced).
mysqlnd
  • Fixed bug #70456 (mysqlnd doesn't activate TCP keep-alive when connecting to a server).
openssl
  • Fixed bug #55259 (openssl extension does not get the DH parameters from DH key resource).
  • Fixed bug #70395 (Missing ARG_INFO for openssl_seal()).
  • Fixed bug #60632 (openssl_seal fails with AES).
  • Fixed bug #68312 (Lookup for openssl.cnf causes a message box).
pdo
  • Fixed bug #70389 (PDO constructor changes unrelated variables).
phar
  • Fixed bug #69720 (Null pointer dereference in phar_get_fp_offset()). (CVE-2015-7803)
  • FIxed bug #70433 (Uninitialized pointer in phar_make_dirstream when zip entry filename is "/"). (CVE-2015-7804)
phpdbg
  • Fix phpdbg_break_next() sometimes not breaking.
standard
  • Fixed bug #67131 (setcookie() conditional for empty values not met).
streams
  • Fixed bug #70361 (HTTP stream wrapper doesn't close keep-alive connections).
zip
  • Fixed bug #70322 (ZipArchive::close() doesn't indicate errors).
PHP 5.6.13
Released 03 Sep, 2015
core
  • Fixed bug #69900 (Too long timeout on pipes).
  • Fixed bug #69487 (SAPI may truncate POST data).
  • Fixed bug #70198 (Checking liveness does not work as expected).
  • Fixed bug #70172 (Use After Free Vulnerability in unserialize()). (CVE-2015-6834)
  • Fixed bug #70219 (Use after free vulnerability in session deserializer). (CVE-2015-6835)
cli server
  • Fixed bug #66606 (Sets HTTP_CONTENT_TYPE but not CONTENT_TYPE).
  • Fixed bug #70264 (CLI server directory traversal).
date
  • Fixed bug #70266 (DateInterval::__construct.interval_spec is not supposed to be optional).
  • Fixed bug #70277 (new DateTimeZone($foo) is ignoring text after null byte).
exif
  • Fixed bug #70385 (Buffer over-read in exif_read_data with TIFF IFD tag byte value of 32 bytes).
gmp
  • Fixed bug #70284 (Use after free vulnerability in unserialize() with GMP).
hash
  • Fixed bug #70312 (HAVAL gives wrong hashes in specific cases).
mcrypt
  • Fixed bug #69833 (mcrypt fd caching not working).
opcache
  • Fixed bug #70237 (Empty while and do-while segmentation fault with opcode on CLI enabled).
pcre
  • Fixed bug #70232 (Incorrect bump-along behavior with \K and empty string match).
  • Fixed bug #70345 (Multiple vulnerabilities related to PCRE functions).
soap
  • Fixed bug #70388 (SOAP serialize_function_call() type confusion / RCE). (CVE-2015-6836)
spl
  • Fixed bug #70290 (Null pointer deref (segfault) in spl_autoload via ob_start).
  • Fixed bug #70303 (Incorrect constructor reflection for ArrayObject).
  • Fixed bug #70365 (Use-after-free vulnerability in unserialize() with SplObjectStorage). (CVE-2015-6834)
  • Fixed bug #70366 (Use-after-free vulnerability in unserialize() with SplDoublyLinkedList). (CVE-2015-6834)
standard
  • Fixed bug #70052 (getimagesize() fails for very large and very small WBMP).
  • Fixed bug #70157 (parse_ini_string() segmentation fault with INI_SCANNER_TYPED).
xslt
  • Fixed bug #69782 (NULL pointer dereference). (CVE-2015-6837, CVE-2015-6838)
zip
  • Fixed bug #70350 (ZipArchive::extractTo allows for directory traversal when creating directories). (CVE-2014-9767)
PHP 5.6.12
Released 06 Aug, 2015
core
  • Fixed bug #70012 (Exception lost with nested finally block).
  • Fixed bug #70002 (TS issues with temporary dir handling).
  • Fixed bug #69793 (Remotely triggerable stack exhaustion via recursive method calls).
  • Fixed bug #69892 (Different arrays compare indentical due to integer key truncation).
  • Fixed bug #70121 (unserialize() could lead to unexpected methods execution / NULL pointer deref).
cli server
  • Fixed bug #69655 (php -S changes MKCALENDAR request method to MKCOL).
  • Fixed bug #64878 (304 responses return Content-Type header).
gd
  • Fixed bug #53156 (imagerectangle problem with point ordering).
  • Fixed bug #66387 (Stack overflow with imagefilltoborder). (CVE-2015-8874)
  • Fixed bug #70102 (imagecreatefromwebm() shifts colors).
  • Fixed bug #66590 (imagewebp() doesn't pad to even length).
  • Fixed bug #66882 (imagerotate by -90 degrees truncates image by 1px).
  • Fixed bug #70064 (imagescale(..., IMG_BICUBIC) leaks memory).
  • Fixed bug #69024 (imagescale segfault with palette based image).
  • Fixed bug #53154 (Zero-height rectangle has whiskers).
  • Fixed bug #67447 (imagecrop() add a black line when cropping).
  • Fixed bug #68714 (copy 'n paste error).
  • Fixed bug #66339 (PHP segfaults in imagexbm).
  • Fixed bug #70047 (gd_info() doesn't report WebP support).
odbc
  • Fixed bug #69975 (PHP segfaults when accessing nvarchar(max) defined columns). (CVE-2015-8879)
openssl
  • Fixed bug #69882 (OpenSSL error "key values mismatch" after openssl_pkcs12_read with extra cert).
  • Fixed bug #70014 (openssl_random_pseudo_bytes() is not cryptographically secure). (CVE-2015-8867)
phar
  • Improved fix for bug #69441.
  • Fixed bug #70019 (Files extracted from archive may be placed outside of destination directory). (CVE-2015-6833)
soap
  • Fixed bug #70081 (SoapClient info leak / null pointer dereference via multiple type confusions).
spl
  • Fixed bug #70068 (Dangling pointer in the unserialization of ArrayObject items). (CVE-2015-6832)
  • Fixed bug #70166 (Use After Free Vulnerability in unserialize() with SPLArrayObject). (CVE-2015-6831)
  • Fixed bug #70168 (Use After Free Vulnerability in unserialize() with SplObjectStorage). (CVE-2015-6831)
  • Fixed bug #70169 (Use After Free Vulnerability in unserialize() with SplDoublyLinkedList). (CVE-2015-6831)
standard
  • Fixed bug #70096 (Repeated iptcembed() adds superfluous FF bytes).
PHP 5.6.11
Released 10 Jul, 2015
core
  • Fixed bug #69768 (escapeshell*() doesn't cater to !).
  • Fixed bug #69703 (Use __builtin_clzl on PowerPC).
  • Fixed bug #69732 (can induce segmentation fault with basic php code).
  • Fixed bug #69642 (Windows 10 reported as Windows 8).
  • Fixed bug #69551 (parse_ini_file() and parse_ini_string() segmentation fault).
  • Fixed bug #69781 (phpinfo() reports Professional Editions of Windows 7/8/8.1/10 as "Business").
  • Fixed bug #69740 (finally in generator (yield) swallows exception in iteration).
  • Fixed bug #69835 (phpinfo() does not report many Windows SKUs).
  • Fixed bug #69892 (Different arrays compare indentical due to integer key truncation).
  • Fixed bug #69874 (Can't set empty additional_headers for mail()), regression from fix to bug #68776.
gd
  • Fixed bug #61221 (imagegammacorrect function loses alpha channel).
gmp
  • Fixed bug #69803 (gmp_random_range() modifies second parameter if GMP number).
mysqlnd
  • Fixed bug #69669 (mysqlnd is vulnerable to BACKRONYM). (CVE-2015-3152)
pcre
  • Fixed Bug #53823 (preg_replace: * qualifier on unicode replace garbles the string).
  • Fixed bug #69864 (Segfault in preg_replace_callback)
pdo_pgsql
  • Fixed bug #69752 (PDOStatement::execute() leaks memory with DML Statements when closeCuror() is u).
  • Fixed bug #69362 (PDO-pgsql fails to connect if password contains a leading single quote).
  • Fixed bug #69344 (PDO PgSQL Incorrect binding numeric array with gaps).
phar
  • Fixed bug #69958 (Segfault in Phar::convertToData on invalid file). (CVE-2015-5589)
  • Fixed bug #69923 (Buffer overflow and stack smashing error in phar_fix_filepath). (CVE-2015-5590)
simplexml
  • Refactored the fix for bug #66084 (simplexml_load_string() mangles empty node name).
spl
  • Fixed bug #69737 (Segfault when SplMinHeap::compare produces fatal error).
  • Fixed bug #67805 (SplFileObject setMaxLineLength). .
  • Fixed bug #69970 (Use-after-free vulnerability in spl_recursive_it_move_forward_ex()).
sqlite3
  • Fixed bug #69972 (Use-after-free vulnerability in sqlite3SafetyCheckSickOrOk()).
PHP 5.6.10
Released 11 Jun, 2015
core
  • Fixed bug #66048 (temp. directory is cached during multiple requests).
  • Fixed bug #69566 (Conditional jump or move depends on uninitialised value in extension trait).
  • Fixed bug #69599 (Strange generator+exception+variadic crash).
  • Fixed bug #69628 (complex GLOB_BRACE fails on Windows).
  • Fixed POST data processing slowdown due to small input buffer size on Windows.
  • Fixed bug #69646 (OS command injection vulnerability in escapeshellarg). (CVE-2015-4642)
  • Fixed bug #69719 (Incorrect handling of paths with NULs). (CVE-2015-4598)
  • FTP
  • Improved fix for bug #69545 (Integer overflow in ftp_genlist() resulting in heap overflow). (CVE-2015-4643)
gd
  • Fixed bug #69479 (GD fails to build with newer libvpx).
iconv
  • Fixed bug #48147 (iconv with //IGNORE cuts the string).
litespeed sapi
  • Fixed bug #68812 (Unchecked return value).
mail
  • Fixed bug #68776 (mail() does not have mail header injection prevention for additional headers).
mcrypt
  • Added file descriptor caching to mcrypt_create_iv()
  • Opcache
  • Fixed bug #69549 (Memory leak with opcache.optimization_level=0xFFFFFFFF).
  • PCRE
  • Upgraded pcrelib to 8.37.
phar
  • Fixed bug #69680 (phar symlink in binary directory broken).
postgres
  • Fixed bug #69667 (segfault in php_pgsql_meta_data). (CVE-2015-4644)
sqlite3
  • Upgrade bundled sqlite to 3.8.10.2. (CVE-2015-3414, CVE-2015-3415, CVE-2015-3416)
PHP 5.6.9
Released 14 May, 2015
core
  • Fixed bug #69467 (Wrong checked for the interface by using Trait).
  • Fixed bug #69420 (Invalid read in zend_std_get_method).
  • Fixed bug #60022 ("use statement [...] has no effect" depends on leading backslash).
  • Fixed bug #67314 (Segmentation fault in gc_remove_zval_from_buffer).
  • Fixed bug #68652 (segmentation fault in destructor).
  • Fixed bug #69419 (Returning compatible sub generator produces a warning).
  • Fixed bug #69472 (php_sys_readlink ignores misc errors from GetFinalPathNameByHandleA).
  • Fixed bug #69364 (PHP Multipart/form-data remote dos Vulnerability). (CVE-2015-4024)
  • Fixed bug #69403 (str_repeat() sign mismatch based memory corruption).
  • Fixed bug #69418 (CVE-2006-7243 fix regressions in 5.4+). (CVE-2015-4025)
  • Fixed bug #69522 (heap buffer overflow in unpack()).
ftp
  • Fixed bug #69545 (Integer overflow in ftp_genlist() resulting in heap overflow). (CVE-2015-4022)
odbc
  • Fixed bug #69354 (Incorrect use of SQLColAttributes with ODBC 3.0).
  • Fixed bug #69474 (ODBC: Query with same field name from two tables returns incorrect result).
  • Fixed bug #69381 (out of memory with sage odbc driver).
openssl
  • Fixed bug #69402 (Reading empty SSL stream hangs until timeout).
pcntl
  • Fixed bug #68598 (pcntl_exec() should not allow null char). (CVE-2015-4026)
phar
  • Fixed bug #69453 (Memory Corruption in phar_parse_tarfile when entry filename starts with null). (CVE-2015-4021)
PHP 5.6.8
Released 16 Apr, 2015
core
  • Fixed bug #66609 (php crashes with __get() and ++ operator in some cases).
  • Fixed bug #68021 (get_browser() browser_name_regex returns non-utf-8 characters).
  • Fixed bug #68917 (parse_url fails on some partial urls).
  • Fixed bug #69134 (Per Directory Values overrides PHP_INI_SYSTEM configuration options).
  • Additional fix for bug #69152 (Type confusion vulnerability in exception::getTraceAsString).
  • Fixed bug #69210 (serialize function return corrupted data when sleep has non-string values).
  • Fixed bug #69212 (Leaking VIA_HANDLER func when exception thrown in __call/... arg passing).
  • Fixed bug #69221 (Segmentation fault when using a generator in combination with an Iterator).
  • Fixed bug #69337 (php_stream_url_wrap_http_ex() type-confusion vulnerability).
  • Fixed bug #69353 (Missing null byte checks for paths in various PHP extensions).
apache2handler
  • Fixed bug #69218 (potential remote code execution with apache 2.4 apache2handler).
curl
  • Implemented FR#69278 (HTTP2 support).
  • Fixed bug #68739 (Missing break / control flow).
  • Fixed bug #69316 (Use-after-free in php_curl related to CURLOPT_FILE/_INFILE/_WRITEHEADER).
date
  • Fixed bug #69336 (Issues with "last day of <monthname>").
enchant
  • Fixed bug #65406 (Enchant broker plugins are in the wrong place in windows builds).
ereg
  • Fixed bug #68740 (NULL Pointer Dereference).
fileinfo
  • Fixed bug #68819 (Fileinfo on specific file causes spurious OOM and/or segfault).
filter
  • Fixed bug #69202 (FILTER_FLAG_STRIP_BACKTICK ignored unless other flags are used).
  • Fixed bug #69203 (FILTER_FLAG_STRIP_HIGH doesn't strip ASCII 127).
mbstring
  • Fixed bug #68846 (False detection of CJK Unified Ideographs Extension E).
opcache
  • Fixed bug #69297 (function_exists strange behavior with OPCache on disabled function).
  • Fixed bug #69281 (opcache_is_script_cached no longer works).
  • Fixed bug #68677 (Use After Free). (CVE-2015-1351)
openssl
  • Fixed bugs #68853, #65137 (Buffered crypto stream data breaks IO polling in stream_select() contexts)
  • Fixed bug #69197 (openssl_pkcs7_sign handles default value incorrectly)
  • Fixed bug #69215 (Crypto servers should send client CA list)
  • Add a check for RAND_egd to allow compiling against LibreSSL
phar
  • Fixed bug #64343 (PharData::extractTo fails for tarball created by BSD tar).
  • Fixed bug #64931 (phar_add_file is too restrictive on filename).
  • Fixed bug #65467 (Call to undefined method cli_arg_typ_string).
  • Fixed bug #67761 (Phar::mapPhar fails for Phars inside a path containing ".tar").
  • Fixed bug #69324 (Buffer Over-read in unserialize when parsing Phar).
  • Fixed bug #69441 (Buffer Overflow when parsing tar/zip/phar in phar_set_inode).
postgres
  • Fixed bug #68741 (Null pointer dereference). (CVE-2015-1352)
soap
  • Fixed bug #69152 (Type Confusion Infoleak Vulnerability in unserialize() with SoapFault).
  • Fixed bug #69293 (NEW segfault when using SoapClient::__setSoapHeader (bisected, regression)).
spl
  • Fixed bug #69227 (Use after free in zval_scan caused by spl_object_storage_get_gc).
sqlite3
  • Fixed bug #68760 (SQLITE segfaults if custom collator throws an exception).
  • Fixed bug #69287 (Upgrade bundled libsqlite to 3.8.8.3).
  • Fixed bug #66550 (SQLite prepared statement use-after-free).
PHP 5.6.7
Released 19 Mar, 2015
core
  • Fixed bug #69174 (leaks when unused inner class use traits precedence).
  • Fixed bug #69139 (Crash in gc_zval_possible_root on unserialize).
  • Fixed bug #69121 (Segfault in get_current_user when script owner is not in passwd with ZTS build).
  • Fixed bug #65593 (Segfault when calling ob_start from output buffering callback).
  • Fixed bug #68986 (pointer returned by php_stream_fopen_temporary_file not validated in memory.c).
  • Fixed bug #68166 (Exception with invalid character causes segv).
  • Fixed bug #69141 (Missing arguments in reflection info for some builtin functions).
  • Fixed bug #68976 (Use After Free Vulnerability in unserialize()). (CVE-2015-2787)
  • Fixed bug #69134 (Per Directory Values overrides PHP_INI_SYSTEM configuration options).
  • Fixed bug #69207 (move_uploaded_file allows nulls in path). (CVE-2015-2348)
cgi
  • Fixed bug #69015 (php-cgi's getopt does not see $argv).
cli
  • Fixed bug #67741 (auto_prepend_file messes up __LINE__).
curl
  • Fixed bug #69088 (PHP_MINIT_FUNCTION does not fully initialize cURL on Win32).
  • Add CURLPROXY_SOCKS4A and CURLPROXY_SOCKS5_HOSTNAME constants if supported by libcurl.
ereg
  • Fixed bug #69248 (heap overflow vulnerability in regcomp.c). (CVE-2015-2305)
fpm
  • Fixed bug #68822 (request time is reset too early).
odbc
  • Fixed bug #68964 (Allowed memory size exhausted with odbc_exec).
opcache
  • Fixed bug #69159 (Opcache causes problem when passing a variable variable to a function).
  • Fixed bug #69125 (Array numeric string as key).
  • Fixed bug #69038 (switch(SOMECONSTANT) misbehaves).
openssl
  • Fixed bug #68912 (Segmentation fault at openssl_spki_new).
  • Fixed bug #61285, #68329, #68046, #41631 (encrypted streams don't observe socket timeouts).
  • Fixed bug #68920 (use strict peer_fingerprint input checks)
  • Fixed bug #68879 (IP Address fields in subjectAltNames not used)
  • Fixed bug #68265 (SAN match fails with trailing DNS dot)
  • Fixed bug #67403 (Add signatureType to openssl_x509_parse)
  • Fixed bug (#69195 Inconsistent stream crypto values across versions)
pgsql
  • Fixed bug #68638 (pg_update() fails to store infinite values).
readline
  • Fixed bug #69054 (Null dereference in readline_(read|write)_history() without parameters).
soap
  • Fixed bug #69085 (SoapClient's __call() type confusion through unserialize()). (CVE-2015-4147, CVE-2015-4148)
spl
  • Fixed bug #69108 ("Segmentation fault" when (de)serializing SplObjectStorage).
  • Fixed bug #68557 (RecursiveDirectoryIterator::seek(0) broken after calling getChildren()).
zip
  • Fixed bug #69253 (ZIP Integer Overflow leads to writing past heap boundary). (CVE-2015-2331)
PHP 5.6.6
Released 19 Feb, 2015
core
  • Removed support for multi-line headers, as the are deprecated by RFC 7230.
  • Fixed bug #67068 (getClosure returns somethings that's not a closure).
  • Fixed bug #68942 (Use after free vulnerability in unserialize() with DateTimeZone). (CVE-2015-0273)
  • Fixed bug #68925 (Mitigation for CVE-2015-0235 – GHOST: glibc gethostbyname buffer overflow).
  • Fixed Bug #67988 (htmlspecialchars() does not respect default_charset specified by ini_set)
  • Added NULL byte protection to exec, system and passthru.
dba
  • Fixed bug #68711 (useless comparisons).
enchant
  • Fixed bug #68552 (heap buffer overflow in enchant_broker_request_dict()). (CVE-2014-9705)
fileinfo
  • Fixed bug #68827 (Double free with disabled ZMM).
  • Fixed bug #67647 (Bundled libmagic 5.17 does not detect quicktime files correctly).
  • Fixed bug #68731 (finfo_buffer doesn't extract the correct mime with some gifs).
fpm
  • Fixed bug #66479 (Wrong response to FCGI_GET_VALUES).
  • Fixed bug #68571 (core dump when webserver close the socket).
json
  • Fixed bug #50224 (json_encode() does not always encode a float as a float) by adding JSON_PRESERVE_ZERO_FRACTION.
libxml
  • Fixed bug #64938 (libxml_disable_entity_loader setting is shared between threads).
mysqli
  • Fixed bug #68114 (linker error on some OS X machines with fixed width decimal support)
  • Fixed bug #68657 (Reading 4 byte floats with Mysqli and libmysqlclient has rounding errors)
opcache
  • Fixed bug with try blocks being removed when extended_info opcode generation is turned on.
pdo_mysql
  • Fixed bug #68750 (PDOMysql with mysqlnd does not allow the usage of named pipes).
phar
  • Fixed bug #68901 (use after free). (CVE-2015-2301)
pgsql
  • Fixed Bug #65199 (pg_copy_from() modifies input array variable)
session
  • Fixed bug #68941 (mod_files.sh is a bash-script)
  • Fixed Bug #66623 (no EINTR check on flock)
  • Fixed bug #68063 (Empty session IDs do still start sessions)
sqlite3
  • Fixed bug #68260 (SQLite3Result::fetchArray declares wrong required_num_args).
standard
  • Fixed bug #65272 (flock() out parameter not set correctly in windows).
  • Fixed bug #69033 (Request may get env. variables from previous requests if PHP works as FastCGI).
streams
  • Fixed bug which caused call after final close on streams filter.
PHP 5.6.5
Released 22 Jan, 2015
core
  • Upgraded crypt_blowfish to version 1.3.
  • Fixed bug #60704 bug with some files path).
  • Fixed bug #65419 (Inside trait, self::class != __CLASS__).
  • Fixed bug #68536 (pack for 64bits integer is broken on bigendian).
  • Fixed bug #55541 (errors spawn MessageBox, which blocks test automation).
  • Fixed bug #68297 (Application Popup provides too few information).
  • Fixed bug #65769 (localeconv() broken in TS builds).
  • Fixed bug #65230 (setting locale randomly broken).
  • Fixed bug #66764 (configure doesn't define EXPANDED_DATADIR / PHP_DATADIR correctly).
  • Fixed bug #68583 (Crash in timeout thread).
  • Fixed bug #65576 (Constructor from trait conflicts with inherited constructor).
  • Fixed bug #68676 (Explicit Double Free). (CVE-2014-9425)
  • Fixed bug #68710 (Use After Free Vulnerability in PHP's unserialize()). (CVE-2015-0231)
cgi
  • Fixed bug #68618 (out of bounds read crashes php-cgi). (CVE-2014-9427)
cli server
  • Fixed bug #68745 (Invalid HTTP requests make web server segfault).
curl
  • Fixed bug #67643 (curl_multi_getcontent returns '' when CURLOPT_RETURNTRANSFER isn't set).
date
  • Implemented FR #68268 (DatePeriod: Getter for start date, end date and interval).
exif
  • Fixed bug #68799: Free called on uninitialized pointer. (CVE-2015-0232)
fileinfo
  • Fixed bug #68398 (msooxml matches too many archives).
  • Fixed bug #68665 (invalid free in libmagic).
  • Fixed bug #68671 (incorrect expression in libmagic).
  • Removed readelf.c and related code from libmagic sources
  • Fixed bug #68735 (fileinfo out-of-bounds memory access). (CVE-2014-9652)
fpm
  • Fixed request #68526 (Implement POSIX Access Control List for UDS).
  • Fixed bug #68751 (listen.allowed_clients is broken).
gd
  • Fixed bug #68601 (buffer read overflow in gd_gif_in.c). (CVE-2014-9709)
  • Fixed request #68656 (Report gd library version).
mbstring
  • Fixed bug #68504 (--with-libmbfl configure option not present on Windows).
opcache
  • Fixed bug #68644 (strlen incorrect : mbstring + func_overload=2 +UTF-8 + Opcache).
  • Fixed bug #67111 (Memory leak when using "continue 2" inside two foreach loops).
openssl
  • Improved handling of OPENSSL_KEYTYPE_EC keys.
pcntl
  • Fixed bug #60509 (pcntl_signal doesn't decrease ref-count of old handler when setting SIG_DFL).
pcre
  • Fixed bug #66679 (Alignment Bug in PCRE 8.34 upstream).
pgsql
  • Fixed bug #68697 (lo_export return -1 on failure).
pdo
  • Fixed bug #68371 (PDO#getAttribute() cannot be called with platform-specifi attribute names).
pdo_mysql
  • Fixed bug #68424 (Add new PDO mysql connection attr to control multi statements option).
spl
  • Fixed bug #66405 (RecursiveDirectoryIterator::CURRENT_AS_PATHNAME breaks the RecursiveIterator).
  • Fixed bug #68479 (Added escape parameter to SplFileObject::fputcsv).
sqlite
  • Fixed bug #68120 (Update bundled libsqlite to 3.8.7.2).
streams
  • Fixed bug #68532 (convert.base64-encode omits padding bytes).
PHP 5.6.4
Released 18 Dec, 2014
core
  • Fixed bug #68091 (Some Zend headers lack appropriate extern "C" blocks).
  • Fixed bug #68104 (Segfault while pre-evaluating a disabled function).
  • Fixed bug #68185 ("Inconsistent insteadof definition."- incorrectly triggered).
  • Fixed bug #68355 (Inconsistency in example php.ini comments).
  • Fixed bug #68370 ("unset($this)" can make the program crash).
  • Fixed bug #68422 (Incorrect argument reflection info for array_multisort()).
  • Fixed bug #68545 (NULL pointer dereference in unserialize.c).
  • Fixed bug #68446 (Array constant not accepted for array parameter default).
  • Fixed bug #68594 (Use after free vulnerability in unserialize()). (CVE-2014-8142)
date
  • Fixed day_of_week function as it could sometimes return negative values internally.
fpm
  • Fixed bug #68381 (fpm_unix_init_main ignores log_level).
  • Fixed bug #68420 (listen=9000 listens to ipv6 localhost instead of all addresses).
  • Fixed bug #68421 (access.format='%R' doesn't log ipv6 address).
  • Fixed bug #68423 (PHP-FPM will no longer load all pools).
  • Fixed bug #68428 (listen.allowed_clients is IPv4 only).
  • Fixed bug #68452 (php-fpm man page is oudated).
  • Fixed request #68458 (Change pm.start_servers default warning to notice).
  • Fixed bug #68463 (listen.allowed_clients can silently result in no allowed access).
  • Fixed request #68391 (php-fpm conf files loading order).
  • Fixed bug #68478 (access.log don't use prefix).
mcrypt
  • Fixed possible read after end of buffer and use after free.
gmp
  • Fixed bug #68419 (build error with gmp 4.1).
pdo_pgsql
  • Fixed bug #67462 (PDO_PGSQL::beginTransaction() wrongly throws exception when not in transaction)
  • Fixed bug #68351 (PDO::PARAM_BOOL and ATTR_EMULATE_PREPARES misbehaving)
session
  • Fixed bug #68331 (Session custom storage callable functions not being called)
soap
  • Fixed bug #68361 (Segmentation fault on SoapClient::__getTypes).
zlib
  • Fixed bug #53829 (Compiling PHP with large file support will replace function gzopen by gzopen64)
PHP 5.6.3
Released 13 Nov, 2014
core
  • Implemented 64-bit format codes for pack() and unpack().
  • Fixed bug #51800 (proc_open on Windows hangs forever).
  • Fixed bug #67633 (A foreach on an array returned from a function not doing copy-on-write).
  • Fixed bug #67739 (Windows 8.1/Server 2012 R2 OS build number reported as 6.2 (instead of 6.3)).
  • Fixed bug #67949 (DOMNodeList elements should be accessible through array notation)
  • Fixed bug #68095 (AddressSanitizer reports a heap buffer overflow in php_getopt()).
  • Fixed bug #68118 ($a->foo .= 'test'; can leave $a->foo undefined).
  • Fixed bug #68129 (parse_url() - incomplete support for empty usernames and passwords)
  • Fixed bug #68365 (zend_mm_heap corrupted after memory overflow in zend_hash_copy).
curl
  • Add CURL_SSLVERSION_TLSv1_0, CURL_SSLVERSION_TLSv1_1, and CURL_SSLVERSION_TLSv1_2 constants if supported by libcurl
fileinfo
  • Fixed bug #66242 (libmagic: don't assume char is signed).
  • Fixed bug #68224 (buffer-overflow in libmagic/readcdf.c caught by AddressSanitizer).
  • Fixed bug #68283 (fileinfo: out-of-bounds read in elf note headers). (CVE-2014-3710)
fpm
  • Fixed bug #65641 (PHP-FPM incorrectly defines the SCRIPT_NAME variable when using Apache, mod_proxy-fcgi and ProxyPass).
  • Implemented FR #55508 (listen and listen.allowed_clients should take IPv6 addresses).
gd
  • Fixed bug #65171 (imagescale() fails without height param).
gmp
  • Implemented gmp_random_range() and gmp_random_bits().
  • Fixed bug #63595 (GMP memory management conflicts with other libraries using GMP).
mysqli
  • Fixed bug #68114 (linker error on some OS X machines with fixed width decimal support)
odbc
  • Fixed bug #68087 (ODBC not correctly reading DATE column when preceded by a VARCHAR column)
openssl
  • Fixed bug #68074 (Allow to use system cipher list instead of hardcoded value).
  • Revert regression introduced by fix of bug #41631
pdo_pgsql
  • Fixed bug #68199 (PDO::pgsqlGetNotify doesn't support NOTIFY payloads)
  • Fixed bug #66584 (Segmentation fault on statement deallocation)
reflection
  • Fixed bug #68103 (Duplicate entry in Reflection for class alias).
spl
  • Fixed bug #68128 (Regression in RecursiveRegexIterator)
PHP 5.6.2
Released 16 Oct, 2014
core
  • Fixed bug #68044 (Integer overflow in unserialize() (32-bits only)). (CVE-2014-3669)
curl
  • Fixed bug #68089 (NULL byte injection - cURL lib).
exif
  • Fixed bug #68113 (Heap corruption in exif_thumbnail()). (CVE-2014-3670)
xmlrpc
  • Fixed bug #68027 (Global buffer overflow in mkgmtime() function). (CVE-2014-3668)
PHP 5.6.1
Released 02 Oct, 2014
core
  • Implemented FR #38409 (parse_ini_file() looses the type of booleans).
  • Fixed bug #65463 (SIGSEGV during zend_shutdown()).
  • Fixed bug #66036 (Crash on SIGTERM in apache process).
  • Fixed bug #67878 (program_prefix not honoured in man pages).
  • Fixed bug #67938 (Segfault when extending interface method with variadic).
  • Fixed bug #67985 (Incorrect last used array index copied to new array after unset).
  • Fixed bug #68088 (New Posthandler Potential Illegal efree() vulnerability). (Mike)
dom
  • Made DOMNode::textContent writeable.
fileinfo
  • Fixed bug #67731 (finfo::file() returns invalid mime type for binary files).
gd
  • Made fontFetch's path parser thread-safe.
gmp
  • Fixed bug #67917 (Using GMP objects with overloaded operators can cause memory exhaustion).
  • Fixed bug #50175 (gmp_init() results 0 on given base and number starting with 0x or 0b).
  • Implemented gmp_import() and gmp_export().
mysqli
  • Fixed bug #67839 (mysqli does not handle 4-byte floats correctly).
openssl
  • Fixed bug #67850 (extension won't build if openssl compiled without SSLv3).
phpdbg
  • Fixed issue krakjoe/phpdbg#111 (compile error without ZEND_SIGNALS).
soap
  • Fixed bug #67955 (SoapClient prepends 0-byte to cookie names).
session
  • Fixed bug #67972 (SessionHandler Invalid memory read create_sid()).
sysvsem
  • Implemented FR #67990 (Add optional nowait argument to sem_acquire).
PHP 5.6.0
Released 28 Aug, 2014
apache2 handler sapi
  • Fixed Apache log issue caused by APR's lack of support for %zu (APR issue https://issues.apache.org/bugzilla/show_bug.cgi?id=56120).
cli server
  • Added some MIME types to the CLI web server.
  • Fixed bug #67079 (Missing MIME types for XML/XSL files).
  • Fixed bug #66830 (Empty header causes PHP built-in web server to hang).
  • Fixed bug #67594 (Unable to access to apache_request_headers() elements).
  • Implemented FR #67429 (CLI server is missing some new HTTP response codes).
  • Fixed Bug #67406 (built-in web-server segfaults on startup).
com
  • Fixed bug #41577 (DOTNET is successful once per server run)
  • Fixed missing type checks in com_event_sink .
  • Fixed bug #66431 (Special Character via COM Interface (CP_UTF8)).
core
  • Improved phpinfo() stylesheets.
  • Fixed bug #67693 (incorrect push to the empty array).
  • Removed inconsistency regarding behaviour of array in constants at run-time.
  • Fixed bug #67497 (eval with parse error causes segmentation fault in generator).
  • Fixed bug #67151 (strtr with empty array crashes).
  • Fixed bug #67407 (Windows 8.1/Server 2012 R2 reported as Windows 8/Server 2012).
  • Fixed bug #66608 (Incorrect behavior with nested "finally" blocks).
  • Implemented FR #34407 (ucwords and Title Case).
  • Fixed bug #67091 (make install fails to install libphp5.so on FreeBSD 10.0).
  • Fixed bug #67368 (Memory leak with immediately dereferenced array in class constant).
  • Fixed bug #67468 (Segfault in highlight_file()/highlight_string()).
  • Fixed bug #67498 (phpinfo() Type Confusion Information Leak Vulnerability).
  • Fixed bug #67551 (php://input temp file will be located in sys_temp_dir instead of upload_tmp_dir).
  • Fixed bug #67169 (array_splice all elements, then []= gives wrong index).
  • Fixed bug #67198 (php://input regression).
  • Fixed bug #67247 (spl_fixedarray_resize integer overflow).
  • Fixed bug #67250 (iptcparse out-of-bounds read).
  • Fixed bug #67252 (convert_uudecode out-of-bounds read).
  • Fixed bug #67249 (printf out-of-bounds read).
  • Implemented FR #64744 (Differentiate between member function call on a null and non-null, non-objects).
  • Fixed bug #67436 (Autoloader isn't called if two method definitions don't match).
  • Fixed bug #66622 (Closures do not correctly capture the late bound class (static::) in some cases).
  • Fixed bug #67390 (insecure temporary file use in the configure script). (Remi)
  • Fixed bug #67392 (dtrace breaks argument unpack).
  • Fixed bug #67428 (header('Location: foo') will override a 308-399 response code).
  • Fixed bug #67433 (SIGSEGV when using count() on an object implementing Countable).
  • Fixed bug #67399 (putenv with empty variable may lead to crash).
  • Expose get_debug_info class hook as __debugInfo() magic method.
  • Implemented unified default encoding (RFC: https://wiki.php.net/rfc/default_encoding).
  • Added T_POW (**) operator (RFC: https://wiki.php.net/rfc/pow-operator).
  • Improved IS_VAR operands fetching.
  • Improved empty string handling. Now ZE uses an interned string instead of allocation new empty string each time.
  • Implemented internal operator overloading (RFC: https://wiki.php.net/rfc/operator_overloading_gmp).
  • Made calls from incompatible context issue an E_DEPRECATED warning instead of E_STRICT (phase 1 of RFC: https://wiki.php.net/rfc/incompat_ctx).
  • Uploads equal or greater than 2GB in size are now accepted.
  • Reduced POST data memory usage by 200-300%. Changed INI setting always_populate_raw_post_data to throw a deprecation warning when enabling and to accept -1 for never populating the $HTTP_RAW_POST_DATA global variable, which will be the default in future PHP versions.
  • Implemented dedicated syntax for variadic functions (RFC: https://wiki.php.net/rfc/variadics).
  • Fixed bug #50333 Improving multi-threaded scalability by using emalloc/efree/estrdup
  • Implemented constant scalar expressions (with support for constants) (RFC: https://wiki.php.net/rfc/const_scalar_exprs).
  • Fixed bug #65784 (Segfault with finally).
  • Fixed bug #66509 (copy() arginfo has changed starting from 5.4).
  • Allow zero length comparison in substr_compare()
  • Fixed bug #60602 (proc_open() changes environment array)
  • Fixed bug #61019 (Out of memory on command stream_get_contents).
  • Fixed bug #64330 (stream_socket_server() creates wrong Abstract Namespace UNIX sockets).
  • Fixed bug #66182 (exit in stream filter produces segfault).
  • Fixed bug #66736 (fpassthru broken).
  • Fixed bug #66822 (Cannot use T_POW in const expression)
  • Fixed bug #67043 (substr_compare broke by previous change)
  • Fixed bug #65701 (copy() doesn't work when destination filename is created by tempnam()).
  • Fixed bug #66015 (Unexpected array indexing in class's static property).
  • Added (constant) string/array dereferencing to static scalar expressions to complete the set; now possible thanks to bug #66015 being fixed.
  • Fixed bug #66568 (Update reflection information for unserialize() function).
  • Fixed bug #66660 (Composer.phar install/update fails).
  • Fixed bug #67024 (getimagesize should recognize BMP files with negative height).
  • Fixed bug #67064 (Countable interface prevents using 2nd parameter ($mode) of count() function).
  • Fixed bug #67072 (Echoing unserialized "SplFileObject" crash).
  • Fixed bug #67033 (Remove reference to Windows 95).
curl
  • Implemented FR #65646 (re-enable CURLOPT_FOLLOWLOCATION with open_basedir or safe_mode).
  • Check for openssl.cafile ini directive when loading CA certs.
  • Remove cURL close policy related constants as these have no effect and are no longer used in libcurl.
  • Fixed bug #66109 (Can't reset CURLOPT_CUSTOMREQUEST to default behaviour)
  • Fix compilation on libcurl versions between 7.10.5 and 7.12.2, inclusive.
  • Fixed bug #64247 (CURLOPT_INFILE doesn't allow reset).
  • Fixed bug #66562 (curl_exec returns differently than curl_multi_getcontent).
date
  • Fixed bug #66060 (Heap buffer over-read in DateInterval). (CVE-2013-6712)
  • Fixed bug #66091 (memory leaks in DateTime constructor) .
  • Fixed bug #67308 (Serialize of DateTime truncates fractions of second).
  • Fixed regression in fix for bug #67118 (constructor can't be called twice).
  • Fixed bug #67251 (date_parse_from_format out-of-bounds read).
  • Fixed bug #67253 (timelib_meridian_with_check out-of-bounds read).
  • Added DateTimeImmutable::createFromMutable to create a DateTimeImmutable object from an existing DateTime (mutable) object
  • Fixed bug #66721 (__wakeup of DateTime segfaults when invalid object data is supplied).
  • Fixed bug #67118 (DateTime constructor crash with invalid data).
dom
  • Fixed bug #67081 (DOMDocumentType->internalSubset returns entire DOCTYPE tag, not only the subset).
embed
  • Fixed bug #65715 (php5embed.lib isn't provided anymore). .
fileinfo
  • Fixed bug #67716 (Segfault in cdf.c). (CVE-2014-3587)
  • Fixed bug #67705 (extensive backtracking in rule regular expression). (CVE-2014-3538)
  • Fixed bug #67327 (fileinfo: CDF infinite loop in nelements DoS).
  • Fixed bug #67328 (fileinfo: fileinfo: numerous file_printf calls resulting in performance degradation).
  • Fixed bug #67326 (fileinfo: cdf_read_short_sector insufficient boundary check).
  • Fixed bug #67329 (fileinfo: NULL pointer deference flaw by processing certain CDF files).
  • Fixed bug #67410 (fileinfo: mconvert incorrect handling of truncated pascal string size). (CVE-2014-3478)
  • Fixed bug #67411 (fileinfo: cdf_check_stream_offset insufficient boundary check). (CVE-2014-3479)
  • Fixed bug #67412 (fileinfo: cdf_count_chain insufficient boundary check). (CVE-2014-3480)
  • Fixed bug #67413 (fileinfo: cdf_read_property_info insufficient boundary check). (CVE-2014-3487)
  • Upgraded to libmagic-5.17
  • Fixed bug #66731 (file: infinite recursion). (CVE-2014-1943)
  • Fixed bug #66820 (out-of-bounds memory access in fileinfo). (CVE-2014-2270).
  • Fixed bug #66946 (fileinfo: extensive backtracking in awk rule regular expression). (CVE-2013-7345)
  • Fixed bug #66987 (Memory corruption in fileinfo ext / bigendian).
  • Fixed bug #66907 (Solaris 10 is missing strcasestr and needs substitute).
  • Fixed bug #66307 (Fileinfo crashes with powerpoint files).
fpm
  • Fixed bug #67606 (revised fix 67541, broke mod_fastcgi BC).
  • Fixed bug #67530 (error_log=syslog ignored).
  • Fixed bug #67635 (php links to systemd libraries without using pkg-config).
  • Fixed bug #67531 (syslog cannot be set in pool configuration).
  • Fixed bug #67541 (Fix Apache 2.4.10+ SetHandler proxy:fcgi:// incompatibilities).
  • Included apparmor support in fpm (RFC: https://wiki.php.net/rfc/fpm_change_hat).
  • Added clear_env configuration directive to disable clearenv() call.
  • Fixed bug #66482 .
  • Fixed bug #66908 (php-fpm reload leaks epoll_create() file descriptor).
  • Fixed bug #67060 (sapi/fpm: possible privilege escalation due to insecure default configuration) (CVE-2014-0185).
  • GD
  • Fixed bug #67730 (Null byte injection possible with imagexxx functions). (CVE-2014-5120)
  • Fixed bug #66901 (php-gd 'c_color' NULL pointer dereference). (CVE-2014-2497)
  • Fixed bug #67248 (imageaffinematrixget missing check of parameters).
  • Fixed imagettftext to load the correct character map rather than the last one.
  • Fixed bug #66356 (Heap Overflow Vulnerability in imagecrop()).
  • Fixed bug #66815 (imagecrop(): insufficient fix for NULL defer). (CVE-2013-7327). .
  • Fixed bug #66869 (Invalid 2nd argument crashes imageaffinematrixget)
  • Fixed bug #66887 (imagescale - poor quality of scaled image).
  • Fixed bug #66890 (imagescale segfault).
  • Fixed bug #66893 (imagescale ignore method argument).
gmp
  • Fixed bug #66872 (invalid argument crashes gmp_testbit)
  • Fixed crashes in serialize/unserialize.
  • Moved GMP to use object as the underlying structure and implemented various improvements based on this. (RFC: https://wiki.php.net/rfc/operator_overloading_gmp).
  • Added gmp_root() and gmp_rootrem() functions for calculating nth roots.
hash
  • Added gost-crypto (CryptoPro S-box) GOST hash algo.
  • Fixed bug #66698 (Missing FNV1a32 and FNV1a64 hash functions). .
  • Implemented timing attack safe string comparison function (RFC: https://wiki.php.net/rfc/timing_attack).
  • hash_pbkdf2() now works correctly if the $length argument is not specified.
intl
  • Fixed bug #66873 (A reproductible crash in UConverter when given invalid encoding)
  • Fixed bug #66921 (Wrong argument type hint for function intltz_from_date_time_zone).
  • Fixed bug #67052 (NumberFormatter::parse() resets LC_NUMERIC setting).
  • Fixed bug #67349 (Locale::parseLocale Double Free).
  • Fixed bug #67397 (Buffer overflow in locale_get_display_name and uloc_getDisplayName (libicu 4.8.1)).
json
  • Fixed case part of bug #64874
  • Fixed bug #65753 (JsonSerializeable couldn't implement on module extension)
  • Fixed bug #66021 (Blank line inside empty array/object when JSON_PRETTY_PRINT is set).
  • ldap
  • Added new function ldap_modify_batch().
  • Fixed issue with null bytes in LDAP bindings.
  • litespeed
  • Updated LiteSpeed SAPI code to V6.6
  • Fixed bug #63228 (-Werror=format-security error in lsapi code).
mail
  • Fixed bug #66535 (Don't add newline after X-PHP-Originating-Script)
mcrypt
  • No longer allow invalid key sizes, invalid IV sizes or missing required IV in mcrypt_encrypt, mcrypt_decrypt and the deprecated mode functions.
  • Use /dev/urandom as the default source for mcrypt_create_iv().
mbstring
  • Upgraded to oniguruma 5.9.5
  • Fixed bug #67199 (mb_regex_encoding mismatch).
milter
  • Fixed bug #67715 (php-milter does not build and crashes randomly).
  • mysqli
  • Added new function mysqli_get_links_stats() as well as new INI variable mysqli.rollback_on_cached_plink of type bool
  • Fixed bug #66762 (Segfault in mysqli_stmt::bind_result() when link closed)
  • Fixed building against an external libmysqlclient.
mysqlnd
  • Disabled flag for SP OUT variables for 5.5+ servers as they are not natively supported by the overlying APIs.
  • Added a new fetching mode to mysqlnd.
  • Added support for gb18030 from MySQL 5.7.
network
  • Fixed bug #67717 (segfault in dns_get_record). (CVE-2014-3597)
  • Fixed bug #67432 (Fix potential segfault in dns_get_record()). (CVE-2014-4049).
  • OCI8
  • Fixed Bug #66875 (Improve performance of multi-row OCI_RETURN_LOB queries)
odbc
  • Fixed bug #60616 (odbc_fetch_into returns junk at end of multi-byte char fields).
openssl
  • Fixed bug #41631 (socket timeouts not honored in blocking SSL reads) .
  • Fixed missing type checks in OpenSSL options .
  • Fixed bug #67609 (TLS connections fail behind HTTP proxy).
  • Fixed broken build against OpenSSL older than 0.9.8 where ECDH unavailable.
  • Fixed bug #67666 (Subject altNames doesn't support wildcard matching).
  • Fixed bug #67224 (Fall back to crypto_type from context if not specified explicitly in stream_socket_enable_crypto).
  • Fixed bug #65698 (certificates validity parsing does not work past 2050).
  • Fixed bug #66636 (openssl_x509_parse warning with V_ASN1_GENERALIZEDTIME).
  • Peer certificates now verified by default in client socket operations (RFC: https://wiki.php.net/rfc/tls-peer-verification).
  • New openssl.cafile and openssl.capath ini directives.
  • Added crypto_method option for the ssl stream context.
  • Added certificate fingerprint support.
  • Added explicit TLSv1.1 and TLSv1.2 stream transports.
  • Fixed bug #65729 (CN_match gives false positive).
  • Peer name verification matches SAN DNS names for certs using the Subject Alternative Name x509 extension.
  • Fixed segfault when built against OpenSSL>=1.0.1
  • Added SPKAC support.
  • Fallback to Windows CA cert store for peer verification if no openssl.cafile ini directive or "cafile" SSL context option specified in Windows.
  • The openssl.cafile and openssl.capath ini directives introduced in alpha2 now have PHP_INI_PERDIR accessibility (was PHP_INI_ALL).
  • New "peer_name" SSL context option replaces "CN_match" (which still works as before but triggers E_DEPRECATED).
  • Fixed segfault when accessing non-existent context for client SNI use
  • Fixed bug #66501 (Add EC key support to php_openssl_is_private_key).
  • Fixed Bug #47030 (add new boolean "verify_peer_name" SSL context option allowing clients to verify cert names separately from the cert itself). "verify_peer_name" is enabled by default for client streams.
  • Fixed Bug #65538 ("cafile" SSL context option now supports stream wrappers).
  • New openssl_get_cert_locations() function to aid CA file and peer verification debugging.
  • Encrypted stream wrappers now disable TLS compression by default.
  • New "capture_session_meta" SSL context option allows encrypted client and server streams access to negotiated protocol/cipher information.
  • New "honor_cipher_order" SSL context option allows servers to prioritize cipher suites of their choosing when negotiating SSL/TLS handshakes.
  • New "single_ecdh_use" and "single_dh_use" SSL context options allow for improved forward secrecy in encrypted stream servers.
  • New "dh_param" SSL context option allows stream servers control over the parameters when negotiating DHE cipher suites.
  • New "ecdh_curve" SSL context option allowing stream servers to specify the curve to use when negotiating ephemeral ECDHE ciphers (defaults to NIST P-256).
  • New "rsa_key_size" SSL context option gives stream servers control over the key size (in bits) used for RSA key agreements.
  • Crypto methods for encrypted client and server streams now use bitwise flags for fine-grained protocol support.
  • Added new tlsv1.0 stream wrapper to specify TLSv1 client/server method. tls wrapper now negotiates TLSv1, TLSv1.1 or TLSv1.2.
  • Encrypted client streams now enable SNI by default.
  • Encrypted streams now prioritize ephemeral key agreement and high strength ciphers by default.
  • New OPENSSL_DEFAULT_STREAM_CIPHERS constant exposes default cipher list.
  • New STREAM_CRYPTO_METHOD_* constants for enhanced control over the crypto methods negotiated encrypted server/client sessions.
  • Encrypted stream servers now automatically mitigate potential DoS vector arising from client-initiated TLS renegotiation. New "reneg_limit", "reneg_window" and "reneg_limit_callback" SSL context options for custom renegotiation limiting control.
  • Fixed memory leak in windows cert verification on verify failure.
  • Peer certificate capturing via SSL context options now functions even if peer verification fails.
  • Encrypted TLS servers now support the server name indication TLS extension via the new "SNI_server_certs" SSL context option.
  • Fixed bug #66833 (Default disgest algo is still MD5, switch to SHA1).
  • Fixed bug #66942 (memory leak in openssl_seal()).
  • Fixed bug #66952 (memory leak in openssl_open()).
  • Fixed bug #66840 (Fix broken build when extension built separately).
opcache
  • Added an optimization of class constants and constant calls to some internal functions
  • Added an optimization pass to convert FCALL_BY_NAME into DO_FCALL.
  • Added an optimization pass to merged identical constants (and related cache_slots) in op_array->literals table.
  • Added script level constant replacement optimization pass.
  • Added function opcache_is_script_cached().
  • Added information about interned strings usage.
  • Fixed bug #67215 (php-cgi work with opcache, may be segmentation fault happen)
pcre
  • Fixed bug #67238 (Ungreedy and min/max quantifier bug, applied patch from the upstream).
  • Upgraded to PCRE 8.34.
  • Added support for (*MARK) backtracking verbs.
pgsql
  • Fixed bug #67550 (Error in code "form" instead of "from", pgsql.c, line 756), which affected builds against libpq < 7.3.
  • pg_insert()/pg_select()/pg_update()/pg_delete() are no longer EXPERIMENTAL.
  • Impremented FR #25854 Return value for pg_insert should be resource instead of bool.
  • Implemented FR #41146 - Add "description" with exteneded flag pg_meta_data(). pg_meta_data(resource $conn, string $table [, bool extended]) It also made pg_meta_data() return "is enum" always.
  • Read-only access to the socket stream underlying database connections is exposed via a new pg_socket() function to allow read/write polling when establishing asynchronous connections and executing queries in non-blocking applications.
  • Asynchronous connections are now possible using the PGSQL_CONNECT_ASYNC flag in conjunction with a new pg_connect_poll() function and connection polling status constants.
  • New pg_flush() and pg_consume_input() functions added to manually complete non-blocking reads/writes to underlying connection sockets.
  • pg_version() returns full report which obtained by PQparameterStatus().
  • Added pg_lo_truncate().
  • Added 64bit large object support for PostgreSQL 9.3 and later.
  • Fixed bug #67555 (Cannot build against libpq 7.3).
  • phpdbg
  • Fixed bug #67575 (Compilation fails for phpdbg when the build directory != src directory).
  • Fixed Bug #67499 (readline feature not enabled when build with libedit).
  • Fix issue krakjoe/phpdbg#94 (List behavior is inconsistent).
  • Fix issue krakjoe/phpdbg#97 (The prompt should always ensure it is on a newline).
  • Fix issue krakjoe/phpdbg#98 (break if does not seem to work).
  • Fix issue krakjoe/phpdbg#99 (register function has the same behavior as run).
  • Fix issue krakjoe/phpdbg#100 (No way to list the current stack/frames) (Help entry was missing).
  • Fixed bug which caused phpdbg to fail immediately on startup in non-debug builds.
  • Fixed bug #67212 (phpdbg uses non-standard TIOCGWINSZ).
  • Included phpdbg sapi (RFC: https://wiki.php.net/rfc/phpdbg).
  • Added watchpoints (watch command).
  • Renamed some commands (next => continue and how to step).
  • Fixed issue #85 (https://github.com/krakjoe/phpdbg/issues/85) (Added stdin/stdout/stderr constants and their php:// wrappers).
pdo
  • Fixed bug #66604 ('pdo/php_pdo_error.h' not copied to the include dir).
pdo-odbc
pdo_pgsql
  • Fixed Bug #42614 (PDO_pgsql: add pg_get_notify support).
  • Fixed Bug #63657 (pgsqlCopyFromFile, pgsqlCopyToArray use Postgres < 7.3 syntax).
  • Cleaned up code by increasing the requirements to libpq versions providing PQexecParams, PQprepare, PQescapeStringConn, PQescapeByteaConn. According to the release notes that means 8.0.8+ or 8.1.4+.
  • Deprecated PDO::PGSQL_ATTR_DISABLE_NATIVE_PREPARED_STATEMENT, an undocument constant effectively equivalent to PDO::ATTR_EMULATE_PREPARES.
  • Added PDO::PGSQL_ATTR_DISABLE_PREPARES constant to execute the queries without preparing them, while still passing parameters separately from the command text using PQexecParams.
pdo_firebird
  • Fixed Bug #66071 (memory corruption in error handling)
phar
  • Fixed bug #64498 ($phar->buildFromDirectory can't compress file with an accent in its name).
  • Fixed bug #67587 (Redirection loop on nginx with FPM).
readline
  • Fixed bug #55496 (Interactive mode doesn't force a newline before the prompt).
  • Fixed bug #67496 (Save command history when exiting interactive shell with control-c).
reflection
  • Implemented FR #67713 (loosen the restrictions on ReflectionClass::newInstanceWithoutConstructor()).
session
  • Fixed bug #67694 (Regression in session_regenerate_id()).
  • Fixed missing type checks in php_session_create_id .
  • Fixed bug #66827 (Session raises E_NOTICE when session name variable is array).
  • Fixed Bug #65315 (session.hash_function silently fallback to default md5)
  • Implemented Request #17860 (Session write short circuit).
  • Implemented Request #20421 (session_abort() and session_reset() function).
  • Remove session_gc() and session_serializer_name() wich were introduced in the first 5.6.0 alpha.
simplexml
  • Fixed bug #66084 (simplexml_load_string() mangles empty node name)
sqlite
  • Updated the bundled libsqlite to the version 3.8.3.1
  • Fixed bug #66967 (Updated bundled libsqlite to 3.8.4.3).
soap
  • Implemented FR #49898 (Add SoapClient::__getCookies()).
spl
  • Revert fix for bug #67064 (BC issues).
  • Fixed bug #67539 (ArrayIterator use-after-free due to object change during sorting). (CVE-2014-4698)
  • Fixed bug #67538 (SPL Iterators use-after-free). (CVE-2014-4670)
  • Fixed bug #67492 (unserialize() SPL ArrayObject / SPLObjectStorage Type Confusion) (CVE-2014-3515).
  • Fixed bug #67359 (Segfault in recursiveDirectoryIterator).
  • Fixed bug #66127 (Segmentation fault with ArrayObject unset).
  • Fixed request #67453 (Allow to unserialize empty data).
  • Added feature #65545 (SplFileObject::fread())
  • Fixed bug #66834 (empty() does not work on classes that extend ArrayObject)
  • Fixed bug #66702 (RegexIterator::INVERT_MATCH does not invert).
standard
  • Implemented FR #65634 (HTTP wrapper is very slow with protocol_version 1.1).
  • Implemented Change crypt() behavior w/o salt RFC. https://wiki.php.net/rfc/crypt_function_salt
  • Implemented request #49824 (Change array_fill() to allow creating empty array).
streams
  • Fixed bug #67430 (http:// wrapper doesn't follow 308 redirects).
tokenizer
  • Fixed bug #67395 (token_name() does not return name for T_POW and T_POW_EQUAL token).
xmlreader
  • Fixed bug #55285 (XMLReader::getAttribute/No/Ns methods inconsistency).
xsl
  • Fixed bug #53965 (<xsl:include> cannot find files with relative paths when loaded with "file://").
zip
  • update libzip to version 1.11.2. PHP don't use any ilibzip private symbol anymore.
  • new method ZipArchive::setPassword($password).
  • add --with-libzip option to build with system libzip.
  • new methods: ZipArchive::setExternalAttributesName($name, $opsys, $attr [, $flags]) ZipArchive::setExternalAttributesIndex($idx, $opsys, $attr [, $flags]) ZipArchive::getExternalAttributesName($name, &$opsys, &$attr [, $flags]) ZipArchive::getExternalAttributesIndex($idx, &$opsys, &$attr [, $flags])
zlib
  • Fixed bug #67865 . Mike
  • Fixed bug #67724 (chained zlib filters silently fail with large amounts of data).
To Top