Modified: web/php/trunk/ChangeLog-5.php =================================================================== --- web/php/trunk/ChangeLog-5.php 2011-08-18 14:01:01 UTC (rev 315141) +++ web/php/trunk/ChangeLog-5.php 2011-08-18 14:06:51 UTC (rev 315142) @@ -11,6 +11,323 @@

PHP 5 ChangeLog

+ +

Version 5.3.7

+18-Aug-2011 + + + + +
  • Apache2 Handler SAPI: + +
  • + +
  • CLI SAPI: + +
  • + +
  • cURL extension: + +
  • + +
  • DateTime extension: + +
  • + +
  • DBA extension: + +
  • + +
  • Exif extesion: + +
  • + +
  • Fileinfo extension: + +
  • + +
  • Filter extension: + +
  • + +
  • Interbase extension: + +
  • + +
  • intl extension: + +
  • + +
  • Imap extension: + +
  • + +
  • json extension: + +
  • + +
  • LDAP extension: + +
  • + +
  • libxml extension: + +
  • + +
  • mbstring extension: + +
  • + +
  • MCrypt extension: + +
  • + +
  • MySQL Improved extension: + +
  • + +
  • mysqlnd + +
  • + +
  • MySQLi extension: + +
  • + +
  • OpenSSL extension: + +
  • + +
  • Oracle Database extension (OCI8): + +
  • + +. PCRE extension: + + + +
  • PDO extension: + +
  • + +
  • PDO DBlib driver: + +
  • + +
  • PDO ODBC driver: + +
  • + +
  • PDO MySQL driver: + +
  • + +
  • PDO PostgreSQL driver: + +
  • + +
  • PDO Oracle driver: + +
  • + +
  • Phar extension: + +
  • + +
  • PHP-FPM SAPI: + +
  • + +
  • Reflection extension: + +
  • + +
  • SOAP extension: + +
  • + +
  • Sockets extension: + +
  • + +
  • SPL extension: + +
  • + +
  • Streams: + +
  • + +

    Version 5.3.6

    17-Mar-2011 Modified: web/php/trunk/archive/archive.xml =================================================================== --- web/php/trunk/archive/archive.xml 2011-08-18 14:01:01 UTC (rev 315141) +++ web/php/trunk/archive/archive.xml 2011-08-18 14:06:51 UTC (rev 315142) @@ -9,6 +9,7 @@ http://php.net/contact php-webmaster@lists.php.net + Added: web/php/trunk/archive/entries/2011-08-18-1.xml =================================================================== --- web/php/trunk/archive/entries/2011-08-18-1.xml (rev 0) +++ web/php/trunk/archive/entries/2011-08-18-1.xml 2011-08-18 14:06:51 UTC (rev 315142) @@ -0,0 +1,71 @@ + + + PHP 5.3.7 Released! + http://www.php.net/archive/2011.php#id2011-08-18-1 + 2011-08-18T10:02:24-04:00 + 2011-08-18T10:02:24-04:00 + + + + + +
    +

    The PHP development team would like to announce the immediate + availability of PHP 5.3.7. This release focuses on improving the + stability of the PHP 5.3.x branch with over 90 bug fixes, some of which + are security related.

    + +

    Security Enhancements and Fixes in PHP 5.3.7:

    +
      +
    • Updated crypt_blowfish to 1.2. (CVE-2011-2483)
    • +
    • Fixed crash in error_log(). Reported by Mateusz Kocielski
    • +
    • Fixed buffer overflow on overlog salt in crypt().
    • +
    • Fixed bug #54939 (File path injection vulnerability in RFC1867 File upload filename). Reported by Krzysztof Kotowicz. (CVE-2011-2202)
    • +
    • Fixed stack buffer overflow in socket_connect(). (CVE-2011-1938)
    • +
    • Fixed bug #54238 (use-after-free in substr_replace()). (CVE-2011-1148)
    • +
    + +

    Key enhancements in PHP 5.3.7 include:

    +
      +
    • Upgraded bundled Sqlite3 to version 3.7.7.1
    • +
    • Upgraded bundled PCRE to version 8.12
    • +
    • Fixed bug #54910 (Crash when calling call_user_func with unknown function name)
    • +
    • Fixed bug #54585 (track_errors causes segfault)
    • +
    • Fixed bug #54262 (Crash when assigning value to a dimension in a non-array)
    • +
    • Fixed a crash inside dtor for error handling
    • +
    • Fixed bug #55339 (Segfault with allow_call_time_pass_reference = Off)
    • +
    • Fixed bug #54935 php_win_err can lead to crash
    • +
    • Fixed bug #54332 (Crash in zend_mm_check_ptr // Heap corruption)
    • +
    • Fixed bug #54305 (Crash in gc_remove_zval_from_buffer)
    • +
    • Fixed bug #54580 (get_browser() segmentation fault when browscap ini directive is set through php_admin_value)
    • +
    • Fixed bug #54529 (SAPI crashes on apache_config.c:197)
    • +
    • Fixed bug #54283 (new DatePeriod(NULL) causes crash).
    • +
    • Fixed bug #54269 (Short exception message buffer causes crash)
    • +
    • Fixed Bug #54221 (mysqli::get_warnings segfault when used in multi queries)
    • +
    • Fixed bug #54395 (Phar::mount() crashes when calling with wrong parameters)
    • +
    • Fixed bug #54384 (Dual iterators, GlobIterator, SplFileObject and SplTempFileObject crash when user-space classes don't call the parent constructor)
    • +
    • Fixed bug #54292 (Wrong parameter causes crash in SplFileObject::__construct())
    • +
    • Fixed bug #54291 (Crash iterating DirectoryIterator for dir name starting with \0)
    • +
    • Fixed bug #54281 (Crash in non-initialized RecursiveIteratorIterator)
    • +
    • Fixed bug #54623 (Segfault when writing to a persistent socket after closing a copy of the socket)
    • +
    • Fixed bug #54681 (addGlob() crashes on invalid flags)
    • +
    • Over 80 other bug fixes.
    • +
    + +

    Windows users: please mind that we do no longer provide builds created + with Visual Studio C++ 6. It is impossible to maintain a high quality + and safe build of PHP for Windows using this unmaintained compiler.

    + +

    For Apache SAPIs (php5_apache2_2.dll), be sure that you use a Visual + Studio C++ 9 version of Apache. We recommend the Apache builds as provided + by ApacheLounge. For any other + SAPI (CLI, FastCGI via mod_fcgi, FastCGI with IIS or other FastCGI capable + server), everything works as before. Third party extension providers + must rebuild their extensions to make them compatible and loadable with + the Visual Studio C++9 builds that we now provide.

    + +

    All PHP users should note that the PHP 5.2 series is NOT supported + anymore. All users are strongly encouraged to upgrade to PHP 5.3.7.

    +
    +
    +
    Modified: web/php/trunk/include/releases.inc =================================================================== --- web/php/trunk/include/releases.inc 2011-08-18 14:01:01 UTC (rev 315141) +++ web/php/trunk/include/releases.inc 2011-08-18 14:06:51 UTC (rev 315142) @@ -2,6 +2,32 @@ $OLDRELEASES = array ( 5 => array ( + '5.3.6' => + array ( + 'announcement' => + array ( + 'English' => '/releases/5_3_6.php', + ), + 'source' => + array ( + 0 => + array ( + 'filename' => 'php-5.3.6.tar.bz2', + 'name' => 'PHP 5.3.6 (tar.bz2)', + 'md5' => '2286f5a82a6e8397955a0025c1c2ad98', + 'date' => '19 March 2011', + ), + 1 => + array ( + 'filename' => 'php-5.3.6.tar.gz', + 'name' => 'PHP 5.3.6 (tar.gz)', + 'md5' => '88a2b00047bc53afbbbdf10ebe28a57e', + 'date' => '19 March 2011', + ), + ), + 'date' => '19 March 2011', + 'museum' => true, + ), '5.3.5' => array ( 'announcement' => Modified: web/php/trunk/include/version.inc =================================================================== --- web/php/trunk/include/version.inc 2011-08-18 14:01:01 UTC (rev 315141) +++ web/php/trunk/include/version.inc 2011-08-18 14:06:51 UTC (rev 315142) @@ -22,15 +22,15 @@ /* PHP 5.3 Release */ -$PHP_5_3_RC = '5.3.7RC5'; // false; +$PHP_5_3_RC = false; $PHP_5_3_RC_DATE = '11 August 2011'; -$PHP_5_3_VERSION = "5.3.6"; -$PHP_5_3_DATE = "17 March 2011"; +$PHP_5_3_VERSION = "5.3.7"; +$PHP_5_3_DATE = "18 August 2011"; $PHP_5_3_MD5 = array( - "tar.bz2" => "2286f5a82a6e8397955a0025c1c2ad98", - "tar.gz" => "88a2b00047bc53afbbbdf10ebe28a57e", + "tar.bz2" => "2d47d003c96de4e88863ff38da61af33", + "tar.gz" => "1ec460bf3a40cea4079ee80076558d51", ); $PHP_5_2_VERSION = "5.2.17"; Added: web/php/trunk/releases/5_3_7.php =================================================================== --- web/php/trunk/releases/5_3_7.php (rev 0) +++ web/php/trunk/releases/5_3_7.php 2011-08-18 14:06:51 UTC (rev 315142) @@ -0,0 +1,68 @@ + + +

    PHP 5.3.7 Release Announcement

    + +

    The PHP development team would like to announce the immediate +availability of PHP 5.3.7. This release focuses on improving the +stability of the PHP 5.3.x branch with over 90 bug fixes, some of which +are security related.

    + +

    Security Enhancements and Fixes in PHP 5.3.7:

    +
      +
    • Updated crypt_blowfish to 1.2. (CVE-2011-2483)
    • +
    • Fixed crash in error_log(). Reported by Mateusz Kocielski
    • +
    • Fixed buffer overflow on overlog salt in crypt().
    • +
    • Fixed bug #54939 (File path injection vulnerability in RFC1867 File upload filename). Reported by Krzysztof Kotowicz. (CVE-2011-2202)
    • +
    • Fixed stack buffer overflow in socket_connect(). (CVE-2011-1938)
    • +
    • Fixed bug #54238 (use-after-free in substr_replace()). (CVE-2011-1148)
    • +
    + +

    Key enhancements in PHP 5.3.7 include:

    +
      +
    • Upgraded bundled Sqlite3 to version 3.7.7.1
    • +
    • Upgraded bundled PCRE to version 8.12
    • +
    • Fixed bug #54910 (Crash when calling call_user_func with unknown function name)
    • +
    • Fixed bug #54585 (track_errors causes segfault)
    • +
    • Fixed bug #54262 (Crash when assigning value to a dimension in a non-array)
    • +
    • Fixed a crash inside dtor for error handling
    • +
    • Fixed bug #55339 (Segfault with allow_call_time_pass_reference = Off)
    • +
    • Fixed bug #54935 php_win_err can lead to crash
    • +
    • Fixed bug #54332 (Crash in zend_mm_check_ptr // Heap corruption)
    • +
    • Fixed bug #54305 (Crash in gc_remove_zval_from_buffer)
    • +
    • Fixed bug #54580 (get_browser() segmentation fault when browscap ini directive is set through php_admin_value)
    • +
    • Fixed bug #54529 (SAPI crashes on apache_config.c:197)
    • +
    • Fixed bug #54283 (new DatePeriod(NULL) causes crash).
    • +
    • Fixed bug #54269 (Short exception message buffer causes crash)
    • +
    • Fixed Bug #54221 (mysqli::get_warnings segfault when used in multi queries)
    • +
    • Fixed bug #54395 (Phar::mount() crashes when calling with wrong parameters)
    • +
    • Fixed bug #54384 (Dual iterators, GlobIterator, SplFileObject and SplTempFileObject crash when user-space classes don't call the parent constructor)
    • +
    • Fixed bug #54292 (Wrong parameter causes crash in SplFileObject::__construct())
    • +
    • Fixed bug #54291 (Crash iterating DirectoryIterator for dir name starting with \0)
    • +
    • Fixed bug #54281 (Crash in non-initialized RecursiveIteratorIterator)
    • +
    • Fixed bug #54623 (Segfault when writing to a persistent socket after closing a copy of the socket)
    • +
    • Fixed bug #54681 (addGlob() crashes on invalid flags)
    • +
    • Over 80 other bug fixes.
    • +
    + +

    Windows users: please mind that we do no longer provide builds created +with Visual Studio C++ 6. It is impossible to maintain a high quality +and safe build of PHP for Windows using this unmaintained compiler.

    + +

    For Apache SAPIs (php5_apache2_2.dll), be sure that you use a Visual +Studio C++ 9 version of Apache. We recommend the Apache builds as provided +by ApacheLounge. For any other +SAPI (CLI, FastCGI via mod_fcgi, FastCGI with IIS or other FastCGI capable +server), everything works as before. Third party extension providers +must rebuild their extensions to make them compatible and loadable with +the Visual Studio C++9 builds that we now provide.

    + +

    All PHP users should note that the PHP 5.2 series is NOT supported +anymore. All users are strongly encouraged to upgrade to PHP 5.3.7.

    + + + Property changes on: web/php/trunk/releases/5_3_7.php ___________________________________________________________________ Added: svn:keywords + Id Rev Revision Added: svn:eol-style + native