Fixed a safe_mode bypass in tempnam() identified by Grzegorz Stachowiak. (Rasmus)
+
Fixed a open_basedir bypass in posix_mkfifo() identified by Grzegorz Stachowiak. (Rasmus)
+
Added "max_file_uploads" INI directive, which can be set to limit the number of file uploads per-request to 20 by default, to prevent possible DOS via temporary file exhaustion. (Ilia)
+
Added protection for $_SESSION from interrupt corruption and improved "session.save_path" check, identified by Stefan Esser. (Stas)
+
(insufficient input string validation of htmlspecialchars()). (Moriyoshi, hello at iwamot dot com)
+
+
+
+
Updated timezone database to version 2009.19 (2009s). (Derick)
+
+
Added LIBXML_PARSEHUGE constant to overrides the maximum text size of a single text node when using libxml2.7.3+. (Kalle)
+
+
Changed "post_max_size" php.ini directive to allow unlimited post size by setting it to 0. (Rasmus)
+
+
Fixed error_log() to be binary safe when using message_type 3. (Jani)
+
Fixed unnecessary invocation of setitimer when timeouts have been disabled. (Arvind Srinivasan)
+
Fixed crash in com_print_typeinfo when an invalid typelib is given. (Pierre)
+
Fixed crash in SQLiteDatabase::ArrayQuery() and SQLiteDatabase::SingleQuery() when calling using Reflection. (Felipe)
+
Fixed crash when instantiating PDORow and PDOStatement through Reflection. (Felipe)
+
Fixed memory leak in openssl_pkcs12_export_to_file(). (Felipe)
+
+
(PDO-ODBC stored procedure call from Solaris 64-bit causes seg fault). (davbrown4 at yahoo dot com, Felipe)
+
(nanosleep not detected properly on some solaris versions). (Jani)
+
(Allow use of ; in values via ;; in PDO DSN). (Ilia, Pierrick)
+
(xmlrpc does not preserve keys in encoded indexed arrays). (Felipe)
+
(xmlrpc_encode_request() changes object into array in calling function). (Felipe)
+
(conflicting types for llabs). (Jani)
+
(isset() and empty() silently casts array to object). (Felipe)
+
(soap call Segmentation fault on a redirected url). (Pierrick)
+
(Compiling with libedit cannot find readline.h). (tcallawa at redhat dot com)
+
(segmentation fault when concatenating very large strings on 64bit linux). (Ilia)
+
(pg_copy_to() fails when table name contains schema. (Ilia)
+
(ldap_get_entries() return false instead of an empty array when there is no error). (Jani)
+
(Incorrectly matched docComment). (Felipe)
+
(FastCGI fails with wrong error on HEAD request to non-existent file). (Dmitry)
+
(Memory leak when fetching timestamp column from Oracle database). (Felipe)
+
(FILTER_VALIDATE_EMAIL fails with valid addresses containing = or ?). (Pierrick)
+
(parse_url() incorrect when ? in fragment). (Ilia)
+
(Segfault caused by uksort()). (Felipe)
+
(Throwing through Reflection modified Exception object makes segmentation fault). (Felipe)
+
(SNMP3 warning message about security level printed twice). (Jani)
+ The PHP development team would like to announce the immediate
+ availability of PHP 5.2.12. This release focuses on improving the stability of
+ the PHP 5.2.x branch with over 60 bug fixes, some of which are security related.
+ All users of PHP 5.2 are encouraged to upgrade to this release.
+
+
+ Security Enhancements and Fixes in PHP 5.2.12:
+
+
+
Fixed a safe_mode bypass in tempnam() identified by Grzegorz Stachowiak. (CVE-2009-3557, Rasmus)
+
Fixed a open_basedir bypass in posix_mkfifo() identified by Grzegorz Stachowiak. (CVE-2009-3558, Rasmus)
+
Added "max_file_uploads" INI directive, which can be set to limit the number of file uploads per-request to 20 by default, to prevent possible DOS via temporary file exhaustion, identified by Bogdan Calin. (CVE-2009-4017, Ilia)
+
Added protection for $_SESSION from interrupt corruption and improved "session.save_path" check, identified by Stefan Esser. (CVE-2009-4143, Stas)
+
Fixed bug #49785 (insufficient input string validation of htmlspecialchars()). (CVE-2009-4142, Moriyoshi, hello at iwamot dot com)
+
+
+
+ Further details about the PHP 5.2.12 release can be found in the release announcement, and the full list of changes are available in the ChangeLog.
+
+The PHP development team would like to announce the immediate
+availability of PHP 5.2.12. This release focuses on improving the stability of
+the PHP 5.2.x branch with over 60 bug fixes, some of which are security related.
+All users of PHP 5.2 are encouraged to upgrade to this release.
+
+
+
+Security Enhancements and Fixes in PHP 5.2.12:
+
+
+
Fixed a safe_mode bypass in tempnam() identified by Grzegorz Stachowiak. (CVE-2009-3557, Rasmus)
+
Fixed a open_basedir bypass in posix_mkfifo() identified by Grzegorz Stachowiak. (CVE-2009-3558, Rasmus)
+
Added "max_file_uploads" INI directive, which can be set to limit the number of file uploads per-request to 20 by default, to prevent possible DOS via temporary file exhaustion, identified by Bogdan Calin. (CVE-2009-4017, Ilia)
+
Added protection for $_SESSION from interrupt corruption and improved "session.save_path" check, identified by Stefan Esser. (CVE-2009-4143, Stas)
+
Fixed bug #49785 (insufficient input string validation of htmlspecialchars()). (CVE-2009-4142, Moriyoshi, hello at iwamot dot com)
+
+
+
+Key enhancements in PHP 5.2.12 include:
+
+
+
Fixed unnecessary invocation of setitimer when timeouts have been disabled. (Arvind Srinivasan)
+
Fixed crash in com_print_typeinfo when an invalid typelib is given. (Pierre)
+
Fixed crash in SQLiteDatabase::ArrayQuery() and SQLiteDatabase::SingleQuery() when calling using Reflection. (Felipe)
+
Fixed crash when instantiating PDORow and PDOStatement through Reflection. (Felipe)
+
Fixed memory leak in openssl_pkcs12_export_to_file(). (Felipe)
+
Fixed bug #50207 (segmentation fault when concatenating very large strings on 64bit linux). (Ilia)
+
Fixed bug #50162 (Memory leak when fetching timestamp column from Oracle database). (Felipe)
+
Fixed bug #50006 (Segfault caused by uksort()). (Felipe)
+
Fixed bug #50005 (Throwing through Reflection modified Exception object makes segmentation fault). (Felipe)
+
Fixed bug #49174 (crash when extending PDOStatement and trying to set queryString property). (Felipe)
+
Fixed bug #49098 (mysqli segfault on error). (Rasmus)
+
+
Over 50 other bug fixes.
+
+
+
+For users upgrading from PHP 5.0 and PHP 5.1, an upgrade guide is available
+here, detailing the changes between those releases
+and PHP 5.2.12.
+
+
+
+ For a full list of changes in PHP 5.2.12, see the ChangeLog.
+
+
+
Property changes on: web/php/trunk/releases/5_2_12.php
___________________________________________________________________
Added: svn:keywords
+ Id Rev Revision
Added: svn:eol-style
+ native
Modified: web/php-bugs/trunk/include/functions.inc
===================================================================
--- web/php-bugs/trunk/include/functions.inc 2009-12-17 12:42:41 UTC (rev 292252)
+++ web/php-bugs/trunk/include/functions.inc 2009-12-17 13:06:28 UTC (rev 292253)
@@ -141,8 +141,7 @@
"5.3.1",
"5.3SVN-{$date} (snap)",
"5.3SVN-{$date} (SVN)",
- "5.2.12RC4",
- "5.2.11",
+ "5.2.12",
"5.2SVN-{$date} (snap)",
"5.2SVN-{$date} (SVN)",
"6SVN-{$date} (snap)",
Modified: web/qa/trunk/include/release-qa.php
===================================================================
--- web/qa/trunk/include/release-qa.php 2009-12-17 12:42:41 UTC (rev 292252)
+++ web/qa/trunk/include/release-qa.php 2009-12-17 13:06:28 UTC (rev 292253)
@@ -7,7 +7,7 @@
// FIXME: Use http://www.php.net/releases/index.php?serialize=1 info here?
// Note: These two variables determine which failed make tests may report to the qa.reports list
-$BUILD_TEST_RELEASES = array(/*'5.3.1',*/'5.2.12RC4');
+$BUILD_TEST_RELEASES = array(/*'5.3.1','5.2.12RC4'*/);
$DEV_RELEASES = array();
foreach($BUILD_TEST_RELEASES as $release) {
@@ -17,9 +17,9 @@
$DEV_RELEASES[] = $release . "-dev";
}
-$RELEASE_PROCESS = array(52 => true, 53 => false);
+$RELEASE_PROCESS = array(52 => false, 53 => false);
-$CURRENT_QA_RELEASE_52 = '5.2.12RC4';
+$CURRENT_QA_RELEASE_52 = false; //'5.2.12RC4';
$RC_FILES_52 = array (
array (
'http://downloads.php.net/ilia/',