(Lack of error context with nested exceptions). (Stas)
+
(Throwing an exception in a destructor causes a fatal error). (Stas)
+
(same parameter name can be used multiple times in method/function definition). (Felipe)
+
+
+
+
Core:
+
+
Added ability to connect to HTTPS sites through proxy with basic authentication using stream_context/http/header/Proxy-Authorization (Dmitry)
+
Changed default value of ini directive serialize_precision from 100 to 17. (Gustavo)
+
(buffer overrun with high values for precision ini setting). (Gustavo)
+
(reflection data for fgetcsv out-of-date). (Richard)
+
(Regression introduced in 5.3.4 in open_basedir with a trailing forward slash). (lekensteyn at gmail dot com, Pierre)
+
(Fix compile on the VAX). (Rasmus, jklos)
+
(array_product() always returns 0 for an empty array). (Ilia)
+
(fwrite() doesn't check reply from ftp server before exiting). (Ilia)
+
+
+
+
Calendar extension:
+
+
(Integer overflow in SdnToJulian, sometimes leading to segfault). (Gustavo)
+
+
+
+
DOM extension:
+
+
Implemented FR (Made DOMDocument::saveHTML accept an optional DOMNode like DOMDocument::saveXML). (Gustavo)
+
+
+
+
DateTime extension:
+
+
Fixed a bug in DateTime->modify() where absolute date/time statements had no effect. (Derick)
+
(DatePeriod fails to initialize recurrences on 64bit big-endian systems). (Derick, rein@basefarm.no)
+
(Segfault when specifying interval as two dates). (Stas)
+
(Can't use new properties in class extended from DateInterval). (Stas)
+
(setDate, setISODate, setTime works wrong when DateTime created from timestamp). (Stas)
+
(DateTime constructor's second argument doesn't have a null default value). (Gustavo, Stas)
+
+
+
+
Exif extension:
+
+
(crash on crafted tag, reported by Luca Carettoni). (Pierre) (CVE-2011-0708)
+
+
+
+
Filter extension:
+
+
(FILTER_VALIDATE_URL doesn't validate port number). (Ilia, Gustavo)
+
(FILTER_FLAG_NO_RES_RANGE is missing some IP ranges). (Ilia)
+
(INPUT_ENV returns NULL for set variables (CLI)). (Ilia)
+
(FILTER_FLAG_NO_RES_RANGE don't work with ipv6). (Ilia, valli at icsurselva dot ch)
+
+
+
+
Fileinfo extension:
+
+
(finfo_file() Cannot determine filetype in archives). (Hannes)
+
+
+
+
Gettext
+
+
(_() crashes on Windows when no LANG or LANGUAGE environment variable are set). (Pierre)
+
+
+
+
IMAP extension:
+
+
Implemented FR (get MIME headers of the part of the email). (Stas)
+
(imap_mime_header_decode() doesn't ignore \t during long MIME header unfolding). (Adam)
+
+
+
+
Intl extension:
+
+
(Segmentation fault when using cloned several intl objects). (Gustavo)
+
(NumberFormatter::setSymbol crash on bogus $attr values). (Felipe)
+
Implemented clone functionality for number, date & message formatters. (Stas).
+
+
+
+
JSON extension:
+
+
(Ensure error_code is always set during some failed decodings). (Scott)
+
+
+
+
mysqlnd
+
+
Fixed problem with always returning 0 as num_rows for unbuffered sets. (Andrey, Ulf)
+
+
+
+
MySQL Improved extension:
+
+
Added 'db' and 'catalog' keys to the field fetching functions (FR ). (Kalle)
+
Fixed buggy counting of affected rows when using the text protocol. The collected statistics were wrong when multi_query was used with mysqlnd (Andrey)
+
(Connect Error from MySqli (mysqlnd) when using SSL). (Kalle)
+
(mysqli::query returns false after successful LOAD DATA query). (Kalle, Andrey)
+
(mysqli_real_connect() ignores client flags when built to call libmysql). (Kalle, tre-php-net at crushedhat dot com)
+
+
+
+
OpenSSL extension:
+
+
Fixed stream_socket_enable_crypto() not honoring the socket timeout in server mode. (Gustavo)
+
(Memory leaks when openssl_encrypt). (Pierre)
+
(Memory leaks when openssl_decrypt). (Pierre)
+
(stream_socket_enable_crypto() busy-waits in client mode). (Gustavo)
+
Implemented FR (Cannot disable SessionTicket extension for servers that do not support it) by adding a no_ticket SSL context option. (Adam, Tony)
+
+
+
+
PDO MySQL driver:
+
+
(PDOStatement execute segfaults for pdo_mysql driver). (Johannes)
+
Implemented FR (Support for setting character sets in DSN strings). (Kalle)
+
+
+
+
PDO Oracle driver:
+
+
(Cannot load Lob data with more than 4000 bytes on ORACLE 10). (spatar at mail dot nnov dot ru)
+
+
+
+
PDO PostgreSQL driver:
+
+
(segfault in pgsql_stmt_execute() when postgres is down). (gyp at balabit dot hu)
+
+
+
Phar extension:
+
+
(format-string vulnerability on Phar). (Felipe) (CVE-2011-1153)
+
(format string bug in ext/phar). (crrodriguez at opensuse dot org, Ilia)
+
(PHAR reports invalid error message, when the directory does not exist). (Ilia)
+
+
+
+
PHP-FPM SAPI:
+
+
Enforce security in the fastcgi protocol parsing. (ef-lists at email dotde)
+
(php-fpm log format now match php_error log format). (fat)
+
(php-fpm --test doesn't set a valuable return value). (fat)
+
(php-fpm slowlog now also logs the original request). (fat)
+
+
+
+
Readline extension:
+
+
(Fixed parameter handling inside readline() function). (jo at feuersee dot de, Ilia)
+
+
+
+
Reflection extension:
+
+
(ReflectionClass::getConstant(s) emits fatal error on constants with self::). (Gustavo)
+
+
+
+
Shmop extension:
+
+
(Integer overflow in shmop_read()). (Felipe) Reported by Jose Carlos Norte (CVE-2011-1092)
+
+
+
+
SNMP extension:
+
+
(snmprealwalk (snmp v1) does not handle end of OID tree correctly). (Boris Lytochkin)
+
+
+
+
SOAP extension:
+
+
Fixed possible crash introduced by the NULL poisoning patch. (Mateusz Kocielski, Pierre)
+
+
+
+
SPL extension:
+
+
Fixed memory leak in DirectoryIterator::getExtension() and SplFileInfo::getExtension(). (Felipe)
+
(SPL assumes HAVE_GLOB is defined). (Chris Jones)
+
(property_exists incorrect on ArrayObject null and 0 values). (Felipe)
The PHP development team would like to announce the immediate
+ availability of PHP 5.3.6. This release focuses on improving the
+ stability of the PHP 5.3.x branch with over 60 bug fixes, some of which
+ are security related.
+
+
Security Enhancements and Fixes in PHP 5.3.6:
+
+
Enforce security in the fastcgi protocol parsing with fpm SAPI.
+
Fixed bug #54247 (format-string vulnerability on Phar). (CVE-2011-1153)
+
Fixed bug #54193 (Integer overflow in shmop_read()). (CVE-2011-1092)
+
Fixed bug #54055 (buffer overrun with high values for precision ini setting).
+
Fixed bug #54002 (crash on crafted tag in exif). (CVE-2011-0708)
+
Fixed bug #53885 (ZipArchive segfault with FL_UNCHANGED on empty archive). (CVE-2011-0421)
+
+
+
Key enhancements in PHP 5.3.6 include:
+
+
Upgraded bundled Sqlite3 to version 3.7.4.
+
Upgraded bundled PCRE to version 8.11.
+
Added ability to connect to HTTPS sites through proxy with basic authentication using stream_context/http/header/Proxy-Authorization.
+
Added options to debug backtrace functions.
+
Changed default value of ini directive serialize_precision from 100 to 17.
+
Fixed Bug #53971 (isset() and empty() produce apparently spurious runtime error).
+
Fixed Bug #53958 (Closures can't 'use' shared variables by value and by reference).
+
Fixed bug #53577 (Regression introduced in 5.3.4 in open_basedir with a trailing forward slash).
+
Over 60 other bug fixes.
+
+
+
Windows users: please mind that we do no longer provide builds created
+ with Visual Studio C++ 6. It is impossible to maintain a high quality
+ and safe build of PHP for Windows using this unmaintained compiler.
+
+
+
For Apache SAPIs (php5_apache2_2.dll), be sure that you use a Visual
+ Studio C++ 9 version of Apache. We recommend the PHP builds as provided
+ by ApacheLounge. For any other SAPI (CLI,
+ FastCGI via mod_fcgi, FastCGI with IIS or other FastCGI capable
+ server), everything works as before. Third party extension providers
+ must rebuild their extensions to make them compatible and loadable with
+ the Visual Studio C++9 builds that we no longer provide.
+
+
+
All PHP users should note that the PHP 5.2 series is NOT supported anymore. All users
+ are strongly encouraged to upgrade to PHP 5.3.6.
The PHP development team would like to announce the immediate
+availability of PHP 5.3.6. This release focuses on improving the
+stability of the PHP 5.3.x branch with over 60 bug fixes, some of which
+are security related.
+
+
Security Enhancements and Fixes in PHP 5.3.6:
+
+
Enforce security in the fastcgi protocol parsing with fpm SAPI.
+
Fixed bug #54247 (format-string vulnerability on Phar). (CVE-2011-1153)
+
Fixed bug #54193 (Integer overflow in shmop_read()). (CVE-2011-1092)
+
Fixed bug #54055 (buffer overrun with high values for precision ini setting).
+
Fixed bug #54002 (crash on crafted tag in exif). (CVE-2011-0708)
+
Fixed bug #53885 (ZipArchive segfault with FL_UNCHANGED on empty archive). (CVE-2011-0421)
+
+
+
Key enhancements in PHP 5.3.6 include:
+
+
Upgraded bundled Sqlite3 to version 3.7.4.
+
Upgraded bundled PCRE to version 8.11.
+
Added ability to connect to HTTPS sites through proxy with basic authentication using stream_context/http/header/Proxy-Authorization.
+
Added options to debug backtrace functions.
+
Changed default value of ini directive serialize_precision from 100 to 17.
+
Fixed Bug #53971 (isset() and empty() produce apparently spurious runtime error).
+
Fixed Bug #53958 (Closures can't 'use' shared variables by value and by reference).
+
Fixed bug #53577 (Regression introduced in 5.3.4 in open_basedir with a trailing forward slash).
+
Over 60 other bug fixes.
+
+
+
Windows users: please mind that we do no longer provide builds created
+with Visual Studio C++ 6. It is impossible to maintain a high quality
+and safe build of PHP for Windows using this unmaintained compiler.
+
+
For Apache SAPIs (php5_apache2_2.dll), be sure that you use a Visual
+Studio C++ 9 version of Apache. We recommend the PHP builds as provided
+by ApacheLounge. For any other
+SAPI (CLI, FastCGI via mod_fcgi, FastCGI with IIS or other FastCGI capable
+server), everything works as before. Third party extension providers
+must rebuild their extensions to make them compatible and loadable with
+the Visual Studio C++9 builds that we no longer provide.
+
+
All PHP users should note that the PHP 5.2 series is NOT supported
+anymore. All users are strongly encouraged to upgrade to PHP 5.3.6.