Modified: web/php/trunk/ChangeLog-5.php =================================================================== --- web/php/trunk/ChangeLog-5.php 2009-12-17 12:42:41 UTC (rev 292252) +++ web/php/trunk/ChangeLog-5.php 2009-12-17 13:06:28 UTC (rev 292253) @@ -176,6 +176,91 @@
+ +

Version 5.2.12

+17-December-2009 + +
+

Version 5.2.11

16-September-2009 Modified: web/php/trunk/archive/archive.xml =================================================================== --- web/php/trunk/archive/archive.xml 2009-12-17 12:42:41 UTC (rev 292252) +++ web/php/trunk/archive/archive.xml 2009-12-17 13:06:28 UTC (rev 292253) @@ -9,6 +9,7 @@ http://php.net/contact php-webmaster@lists.php.net + Added: web/php/trunk/archive/entries/2009-12-17-1.xml =================================================================== --- web/php/trunk/archive/entries/2009-12-17-1.xml (rev 0) +++ web/php/trunk/archive/entries/2009-12-17-1.xml 2009-12-17 13:06:28 UTC (rev 292253) @@ -0,0 +1,34 @@ + + + PHP 5.2.12 Released! + http://www.php.net/archive/2009.php#id2009-12-17-1 + 2009-12-17T07:41:36-05:00 + 2009-12-17T07:41:36-05:00 + + + + +
+

+ The PHP development team would like to announce the immediate + availability of PHP 5.2.12. This release focuses on improving the stability of + the PHP 5.2.x branch with over 60 bug fixes, some of which are security related. + All users of PHP 5.2 are encouraged to upgrade to this release. +

+

+ Security Enhancements and Fixes in PHP 5.2.12: +

+
    +
  • Fixed a safe_mode bypass in tempnam() identified by Grzegorz Stachowiak. (CVE-2009-3557, Rasmus)
  • +
  • Fixed a open_basedir bypass in posix_mkfifo() identified by Grzegorz Stachowiak. (CVE-2009-3558, Rasmus)
  • +
  • Added "max_file_uploads" INI directive, which can be set to limit the number of file uploads per-request to 20 by default, to prevent possible DOS via temporary file exhaustion, identified by Bogdan Calin. (CVE-2009-4017, Ilia)
  • +
  • Added protection for $_SESSION from interrupt corruption and improved "session.save_path" check, identified by Stefan Esser. (CVE-2009-4143, Stas)
  • +
  • Fixed bug #49785 (insufficient input string validation of htmlspecialchars()). (CVE-2009-4142, Moriyoshi, hello at iwamot dot com)
  • +
+ +

+ Further details about the PHP 5.2.12 release can be found in the release announcement, and the full list of changes are available in the ChangeLog. +

+
+
+
Modified: web/php/trunk/include/releases.inc =================================================================== --- web/php/trunk/include/releases.inc 2009-12-17 12:42:41 UTC (rev 292252) +++ web/php/trunk/include/releases.inc 2009-12-17 13:06:28 UTC (rev 292253) @@ -2,6 +2,82 @@ $OLDRELEASES = array ( 5 => array ( + '5.2.11' => + array ( + 'announcement' => + array ( + 'English' => '/releases/5_2_11.php', + ), + 'source' => + array ( + 0 => + array ( + 'filename' => 'php-5.2.11.tar.bz2', + 'name' => 'PHP 5.2.11 (tar.bz2)', + 'md5' => '286bf34630f5643c25ebcedfec5e0a09', + 'date' => '17 September 2009', + ), + 1 => + array ( + 'filename' => 'php-5.2.11.tar.gz', + 'name' => 'PHP 5.2.11 (tar.gz)', + 'md5' => '0223d71f0d6987c06c54b7557ff47f1d', + 'date' => '17 September 2009', + ), + ), + 'windows' => + array ( + 0 => + array ( + 'filename' => 'php-5.2.11-Win32.zip', + 'name' => 'PHP 5.2.11 zip package', + 'md5' => 'adac50ae1449b76f10ff1865bb4f94f1', + 'date' => '17 September 2009', + 'note' => 'The PECL package will not be released for +this version. The 5.2.6 PECL package does however work with this release', + ), + 1 => + array ( + 'filename' => 'php-5.2.11-win32-installer.msi', + 'name' => 'PHP 5.2.11 installer', + 'md5' => '3cedc71fc90f88239d629cdb735d87c0', + 'date' => '17 September 2009', + 'note' => '', + ), + 2 => + array ( + 'filename' => 'php-debug-pack-5.2.11-Win32.zip', + 'name' => 'PHP 5.2.11 Win32 Debug Pack', + 'md5' => '38cb1b783dd08dff41f445b582d2ffed', + 'date' => '17 September 2009', + ), + 3 => + array ( + 'filename' => 'php-5.2.11-nts-Win32.zip', + 'name' => 'PHP 5.2.11 Non-thread-safe zip package', + 'md5' => 'b724475450a13af4cd99c518fd495340', + 'date' => '17 September 2009', + 'note' => 'The PECL package will not be released for +this version. The 5.2.6 PECL package does however work with this release', + ), + 4 => + array ( + 'filename' => 'php-5.2.11-nts-win32-installer.msi', + 'name' => 'PHP 5.2.11 Non-thread-safe installer', + 'md5' => '4fe1344093e26c2a51a82094bac131ad', + 'date' => '17 September 2009', + ), + 5 => + array ( + 'filename' => 'php-debug-pack-5.2.11-nts-Win32.zip', + 'name' => 'PHP 5.2.11 Non-thread-safe Win32 Debug Pack', + 'md5' => '19d026d6e4322dc64694010ae254e978', + 'date' => '17 September 2009', + ), + ), + 'date' => '17 September 2009', + 'museum' => true, + ), '5.3.0' => array ( 'announcement' => @@ -26,7 +102,7 @@ ), ), 'date' => '30 June 2009', - 'museum' => false, + 'museum' => true, ), '5.2.10' => array ( @@ -102,7 +178,7 @@ ), ), 'date' => '18 June 2009', - 'museum' => false, + 'museum' => true, ), '5.2.9' => array ( Modified: web/php/trunk/include/version.inc =================================================================== --- web/php/trunk/include/version.inc 2009-12-17 12:42:41 UTC (rev 292252) +++ web/php/trunk/include/version.inc 2009-12-17 13:06:28 UTC (rev 292253) @@ -29,23 +29,23 @@ ); /* PHP 5.2 Release */ -$PHP_5_2_RC = '5.2.12RC4'; +$PHP_5_2_RC = false; // '5.2.12RC4'; $PHP_5_2_RC_DATE = "10 Dec 2009"; -$PHP_5_2_VERSION = "5.2.11"; -$PHP_5_2_DATE = "17 September 2009"; +$PHP_5_2_VERSION = "5.2.12"; +$PHP_5_2_DATE = "17 December 2009"; $PHP_5_2_WINDOWS_DATE = $PHP_5_2_DATE; $PHP_5_2_WINDOWS_VERSION = $PHP_5_2_VERSION; $PHP_5_2_MD5 = array( - "tar.bz2" => "286bf34630f5643c25ebcedfec5e0a09", - "tar.gz" => "0223d71f0d6987c06c54b7557ff47f1d", - "zip" => "adac50ae1449b76f10ff1865bb4f94f1", - "installer" => "3cedc71fc90f88239d629cdb735d87c0", - "nts.zip" => "b724475450a13af4cd99c518fd495340", - "nts.installer" => "4fe1344093e26c2a51a82094bac131ad", - "debugpack" => "38cb1b783dd08dff41f445b582d2ffed", - "nts.debugpack" => "19d026d6e4322dc64694010ae254e978", + "tar.bz2" => "5b7077e366c7eeab34da31dd860a1923", + "tar.gz" => "e6d6cc6570c77f60d8d4c99565d42ffd", + "zip" => "e04f2944175dc19d7d007b5e889690b4", + "installer" => "df73529935bb855842e38afda8a295d7", + "nts.zip" => "ff0c67bb622c062f0820598e8d6bc12c", + "nts.installer" => "418656307a52c99f2175c748da31a9d8", + "debugpack" => "b21a5abb9e5bae4c657d0983986c4434", + "nts.debugpack" => "e2620df81442ddefc0c3450be58540f9", ); $PHP_5_2_WINDOWS_NOTE_MSI = ""; Added: web/php/trunk/releases/5_2_12.php =================================================================== --- web/php/trunk/releases/5_2_12.php (rev 0) +++ web/php/trunk/releases/5_2_12.php 2009-12-17 13:06:28 UTC (rev 292253) @@ -0,0 +1,56 @@ + + +

PHP 5.2.12 Release Announcement

+

+The PHP development team would like to announce the immediate +availability of PHP 5.2.12. This release focuses on improving the stability of +the PHP 5.2.x branch with over 60 bug fixes, some of which are security related. +All users of PHP 5.2 are encouraged to upgrade to this release. +

+ +

+Security Enhancements and Fixes in PHP 5.2.12: +

+
    +
  • Fixed a safe_mode bypass in tempnam() identified by Grzegorz Stachowiak. (CVE-2009-3557, Rasmus)
  • +
  • Fixed a open_basedir bypass in posix_mkfifo() identified by Grzegorz Stachowiak. (CVE-2009-3558, Rasmus)
  • +
  • Added "max_file_uploads" INI directive, which can be set to limit the number of file uploads per-request to 20 by default, to prevent possible DOS via temporary file exhaustion, identified by Bogdan Calin. (CVE-2009-4017, Ilia)
  • +
  • Added protection for $_SESSION from interrupt corruption and improved "session.save_path" check, identified by Stefan Esser. (CVE-2009-4143, Stas)
  • +
  • Fixed bug #49785 (insufficient input string validation of htmlspecialchars()). (CVE-2009-4142, Moriyoshi, hello at iwamot dot com)
  • +
+ +

+Key enhancements in PHP 5.2.12 include: +

+
    +
  • Fixed unnecessary invocation of setitimer when timeouts have been disabled. (Arvind Srinivasan)
  • +
  • Fixed crash in com_print_typeinfo when an invalid typelib is given. (Pierre)
  • +
  • Fixed crash in SQLiteDatabase::ArrayQuery() and SQLiteDatabase::SingleQuery() when calling using Reflection. (Felipe)
  • +
  • Fixed crash when instantiating PDORow and PDOStatement through Reflection. (Felipe)
  • +
  • Fixed memory leak in openssl_pkcs12_export_to_file(). (Felipe)
  • +
  • Fixed bug #50207 (segmentation fault when concatenating very large strings on 64bit linux). (Ilia)
  • +
  • Fixed bug #50162 (Memory leak when fetching timestamp column from Oracle database). (Felipe)
  • +
  • Fixed bug #50006 (Segfault caused by uksort()). (Felipe)
  • +
  • Fixed bug #50005 (Throwing through Reflection modified Exception object makes segmentation fault). (Felipe)
  • +
  • Fixed bug #49174 (crash when extending PDOStatement and trying to set queryString property). (Felipe)
  • +
  • Fixed bug #49098 (mysqli segfault on error). (Rasmus)
  • + +
  • Over 50 other bug fixes.
  • +
+ +

+For users upgrading from PHP 5.0 and PHP 5.1, an upgrade guide is available +here, detailing the changes between those releases +and PHP 5.2.12. +

+ +

+ For a full list of changes in PHP 5.2.12, see the ChangeLog. +

+ + Property changes on: web/php/trunk/releases/5_2_12.php ___________________________________________________________________ Added: svn:keywords + Id Rev Revision Added: svn:eol-style + native Modified: web/php-bugs/trunk/include/functions.inc =================================================================== --- web/php-bugs/trunk/include/functions.inc 2009-12-17 12:42:41 UTC (rev 292252) +++ web/php-bugs/trunk/include/functions.inc 2009-12-17 13:06:28 UTC (rev 292253) @@ -141,8 +141,7 @@ "5.3.1", "5.3SVN-{$date} (snap)", "5.3SVN-{$date} (SVN)", - "5.2.12RC4", - "5.2.11", + "5.2.12", "5.2SVN-{$date} (snap)", "5.2SVN-{$date} (SVN)", "6SVN-{$date} (snap)", Modified: web/qa/trunk/include/release-qa.php =================================================================== --- web/qa/trunk/include/release-qa.php 2009-12-17 12:42:41 UTC (rev 292252) +++ web/qa/trunk/include/release-qa.php 2009-12-17 13:06:28 UTC (rev 292253) @@ -7,7 +7,7 @@ // FIXME: Use http://www.php.net/releases/index.php?serialize=1 info here? // Note: These two variables determine which failed make tests may report to the qa.reports list -$BUILD_TEST_RELEASES = array(/*'5.3.1',*/'5.2.12RC4'); +$BUILD_TEST_RELEASES = array(/*'5.3.1','5.2.12RC4'*/); $DEV_RELEASES = array(); foreach($BUILD_TEST_RELEASES as $release) { @@ -17,9 +17,9 @@ $DEV_RELEASES[] = $release . "-dev"; } -$RELEASE_PROCESS = array(52 => true, 53 => false); +$RELEASE_PROCESS = array(52 => false, 53 => false); -$CURRENT_QA_RELEASE_52 = '5.2.12RC4'; +$CURRENT_QA_RELEASE_52 = false; //'5.2.12RC4'; $RC_FILES_52 = array ( array ( 'http://downloads.php.net/ilia/',