com web/php: 7.0.12 announcement: ChangeLog-7.php archive/archive.xml archive/entries/2016-10-13-1.xml include/releases.inc include/version.inc
releases/7_0_12.php

From: Date: Thu, 13 Oct 2016 19:54:28 +0000
Subject: com web/php: 7.0.12 announcement: ChangeLog-7.php archive/archive.xml archive/entries/2016-10-13-1.xml include/releases.inc include/version.inc
releases/7_0_12.php
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-25236@lists.php.net to get a copy of this message
Commit: 0232389f33176233ea43c49e35d448f6ed4e4f3d Author: Anatol Belski <ab@php.net> Thu, 13 Oct 2016 21:54:28 +0200 Parents: c108eab088fe45659fd3ee5f1ccbdcbd3e970ac2 Branches: master Link: http://git.php.net/?p=web/php.git;a=commitdiff;h=0232389f33176233ea43c49e35d448f6ed4e4f3d Log: 7.0.12 announcement Changed paths: M ChangeLog-7.php M archive/archive.xml A archive/entries/2016-10-13-1.xml M include/releases.inc M include/version.inc A releases/7_0_12.php

diff --git a/ChangeLog-7.php b/ChangeLog-7.php index d56005d..8e5c78b 100644 --- a/ChangeLog-7.php +++ b/ChangeLog-7.php @@ -7,6 +7,127 @@ site_header("PHP 7 ChangeLog", array("current" => "docs", "css" => array("change <h1>PHP 7 ChangeLog</h1> +<section class="version" id="7.0.12"><!-- {{{ 7.0.12 --> +<h3>Version 7.0.12</h3> +<b><?php release_date('13-Oct-2016'); ?></b> +<ul><li>Core: +<ul> + <li><?php bugfix(73025); ?> (Heap Buffer Overflow in virtual_popen of zend_virtual_cwd.c).</li> + <li><?php bugfix(72703); ?> (Out of bounds global memory read in BF_crypt triggered by password_verify).</li> + <li><?php bugfix(73058); ?> (crypt broken when salt is 'too' long).</li> + <li><?php bugfix(69579); ?> (Invalid free in extension trait).</li> + <li><?php bugfix(73156); ?> (segfault on undefined function).</li> + <li><?php bugfix(73163); ?> (PHP hangs if error handler throws while accessing undef const in default value).</li> + <li><?php bugfix(73172); ?> (parse error: Invalid numeric literal).</li> + <li>Fixed for #73240 (Write out of bounds at number_format).</li> + <li><?php bugfix(73147); ?> (Use After Free in PHP7 unserialize()).</li> + <li><?php bugfix(73189); ?> (Memcpy negative size parameter php_resolve_path).</li> +</ul></li> +<li>BCmath: +<ul> +<li><?php bugfix(73190); ?> (memcpy negative parameter _bc_new_num_ex).</li> +</ul></li> +<li>COM: +<ul> + <li><?php bugfix(73126); ?> (Cannot pass parameter 1 by reference).</li> +</ul></li> +<li>Date: +<ul> + <li><?php bugfix(73091); ?> (Unserializing DateInterval object may lead to __toString invocation).</li> +</ul></li> +<li>DOM: +<ul> + <li><?php bugfix(73150); ?> (missing NULL check in dom_document_save_html).</li> +</ul></li> +<li>Filter: +<ul> + <li><?php bugfix(72972); ?> (Bad filter for the flags FILTER_FLAG_NO_RES_RANGE and FILTER_FLAG_NO_PRIV_RANGE).</li> + <li><?php bugfix(73054); ?> (default option ignored when object passed to int filter).</li> +</ul></li> +<li>GD: +<ul> + <li><?php bugfix(67325); ?> (imagetruecolortopalette: white is duplicated in palette).</li> + <li><?php bugfix(50194); ?> (imagettftext broken on transparent background w/o alphablending).</li> + <li><?php bugfix(73003); ?> (Integer Overflow in gdImageWebpCtx of gd_webp.c).</li> + <li><?php bugfix(53504); ?> (imagettfbbox gives incorrect values for bounding box).</li> + <li><?php bugfix(73157); ?> (imagegd2() ignores 3rd param if 4 are given).</li> + <li><?php bugfix(73155); ?> (imagegd2() writes wrong chunk sizes on boundaries).</li> + <li><?php bugfix(73159); ?> (imagegd2(): unrecognized formats may result in corrupted files).</li> + <li><?php bugfix(73161); ?> (imagecreatefromgd2() may leak memory).</li> +</ul></li> +<li>Intl: +<ul> + <li><?php bugfix(73218); ?> (add mitigation for ICU int overflow).</li> +</ul></li> +<li>Mbstring: +<ul> + <li><?php bugfix(66797); ?> (mb_substr only takes 32-bit signed integer).</li> + <li><?php bugfix(66964); ?> (mb_convert_variables() cannot detect recursion).</li> + <li><?php bugfix(72992); ?> (mbstring.internal_encoding doesn't inherit default_charset).</li> +</ul></li> +<li>Mysqlnd: +<ul> + <li><?php bugfix(72489); ?> (PHP Crashes When Modifying Array Containing MySQLi Result Data).</li> +</ul></li> +<li>Opcache: +<ul> + <li><?php bugfix(72982); ?> (Memory leak in zend_accel_blacklist_update_regexp() function).</li> +</ul></li> +<li>OpenSSL: +<ul> + <li><?php bugfix(73072); ?> (Invalid path SNI_server_certs causes segfault).</li> + <li><?php bugfix(73276); ?> (crash in openssl_random_pseudo_bytes function).</li> + <li><?php bugfix(73275); ?> (crash in openssl_encrypt function).</li> +</ul></li> +<li>PCRE: +<ul> + <li><?php bugfix(73121); ?> (Bundled PCRE doesn't compile because JIT isn't supported on s390).</li> + <li><?php bugfix(73174); ?> (heap overflow in php_pcre_replace_impl).</li> +</ul></li> +<li>PDO_DBlib: +<ul> + <li><?php bugfix(72414); ?> (Never quote values as raw binary data).</li> + <li>Allow \PDO::setAttribute() to set query timeouts.</li> + <li>Handle SQLDECIMAL/SQLNUMERIC types, which are used by later TDS versions.</li> + <li>Add common PDO test suite.</li> + <li>Free error and message strings when cleaning up PDO instances.</li> + <li><?php bugfix(67130); ?> (\PDOStatement::nextRowset() should succeed when all rows in current rowset haven't been fetched).</li> + <li>Ignore potentially misleading dberr values.</li> +</ul></li> +<li>phpdbg: +<ul> + <li><?php bugfix(72996); ?> (phpdbg_prompt.c undefined reference to DL_LOAD).</li> + <li>Fixed next command not stopping when leaving function.</li> +</ul></li> +<li>Session: +<ul> + <li><?php bugfix(68015); ?> (Session does not report invalid uid for files save handler).</li> + <li><?php bugfix(73100); ?> (session_destroy null dereference in ps_files_path_create).</li> +</ul></li> +<li>SimpleXML: +<ul> + <li><?php bugfix(73293); ?> (NULL pointer dereference in SimpleXMLElement::asXML()).</li> +</ul></li> +<li>SOAP: +<ul> + <li><?php bugfix(71711); ?> (Soap Server Member variables reference bug).</li> + <li><?php bugfix(71996); ?> (Using references in arrays doesn't work like expected).</li> +</ul></li> +<li>SPL: +<ul> +<li><?php bugfix(73257); ?>, <?php bugfix(73258); ?> (SplObjectStorage unserialize allows use of non-object as key).</li> +</ul></li> +<li>SQLite3: +<ul> + <li>Updated bundled SQLite3 to 3.14.2.</li> +</ul></li> +<li>Zip: +<ul> + <li><?php bugfix(70752); ?> (Depacking with wrong password leaves 0 length files).</li> +</ul></li> +</ul> +<!-- }}} --></section> + <section class="version" id="7.0.11"><!-- {{{ 7.0.11 --> <h3>Version 7.0.11</h3> <b><?php release_date('15-Sep-2016'); ?></b> diff --git a/archive/archive.xml b/archive/archive.xml index a463700..8e61dab 100644 --- a/archive/archive.xml +++ b/archive/archive.xml @@ -9,6 +9,7 @@ <uri>http://php.net/contact</uri> <email>php-webmaster@lists.php.net</email> </author> + <xi:include href="entries/2016-10-13-1.xml"/> <xi:include href="entries/2016-09-29-1.xml"/> <xi:include href="entries/2016-09-22-1.xml"/> <xi:include href="entries/2016-09-16-2.xml"/> diff --git a/archive/entries/2016-10-13-1.xml b/archive/entries/2016-10-13-1.xml new file mode 100644 index 0000000..fa4dc18 --- /dev/null +++ b/archive/entries/2016-10-13-1.xml @@ -0,0 +1,25 @@ +<?xml version="1.0" encoding="utf-8"?> +<entry xmlns="http://www.w3.org/2005/Atom"> + <title>PHP 7.0.12 Released</title> + <id>http://php.net/archive/2016.php#id2016-10-13-1</id> + <published>2016-10-13T23:00:00+01:00</published> + <updated>2016-10-13T23:00:00+01:00</updated> + <category term="releases" label="New PHP release"/> + <category term="frontpage" label="PHP.net frontpage news"/> + <link href="http://php.net/index.php#id2016-10-13-1" rel="alternate" type="text/html"/> + <link href="http://php.net/archive/2016.php#id2016-10-13-1" rel="via" type="text/html"/> + <content type="xhtml"> + <div xmlns="http://www.w3.org/1999/xhtml"> + <p>The PHP development team announces the immediate availability of PHP + 7.0.12. This is a security release. Several security bugs were fixed in + this release. + + All PHP 7.0 users are encouraged to upgrade to this version.</p> + + <p>For source downloads of PHP 7.0.12 please visit our <a href="http://www.php.net/downloads.php">downloads page</a>, + Windows source and binaries can be found on <a href="http://windows.php.net/download/">windows.php.net/download/</a>. + The list of changes is recorded in the <a href="http://www.php.net/ChangeLog-7.php#7.0.12">ChangeLog</a>. + </p> + </div> + </content> +</entry> diff --git a/include/releases.inc b/include/releases.inc index 1c9ffd5..c717da9 100644 --- a/include/releases.inc +++ b/include/releases.inc @@ -2,6 +2,42 @@ $OLDRELEASES = array ( 7 => array ( + '7.0.11' => + array ( + 'announcement' => + array ( + 'English' => '/releases/7_0_11.php', + ), + 'source' => + array ( + 0 => + array ( + 'filename' => 'php-7.0.11.tar.bz2', + 'name' => 'PHP 7.0.11 (tar.bz2)', + 'md5' => 'daec0bee2e5cbec4b25535b9556f38bd', + 'sha256' => 'f99b729dc1149858844b18af1e8c0de6dd1cdfdd52e22fbb4de2aa78bf9bf7f1', + 'date' => '15 Sep 2016', + ), + 1 => + array ( + 'filename' => 'php-7.0.11.tar.gz', + 'name' => 'PHP 7.0.11 (tar.gz)', + 'md5' => 'c2f285a11f05fe0f4f8a5d36a6814781', + 'sha256' => '02d27b5d140dbad8d400a95af808e1e9ce87aa8d2a2100870734ba26e6700d79', + 'date' => '15 Sep 2016', + ), + 2 => + array ( + 'filename' => 'php-7.0.11.tar.xz', + 'name' => 'PHP 7.0.11 (tar.xz)', + 'md5' => '9a6013a5e9f258bbfb62ae5ac66b72da', + 'sha256' => 'd4cccea8da1d27c11b89386f8b8e95692ad3356610d571253d00ca67d524c735', + 'date' => '15 Sep 2016', + ), + ), + 'date' => '15 Sep 2016', + 'museum' => false, + ), '7.0.10' => array ( 'announcement' => diff --git a/include/version.inc b/include/version.inc index a9cae7b..b8298ae 100644 --- a/include/version.inc +++ b/include/version.inc @@ -18,21 +18,21 @@ */ /* PHP 7.0 Release */ -$PHP_7_0_RC = "7.0.12RC1"; // Current RC version (e.g., '5.6.7RC1') or false +$PHP_7_0_RC = false; // Current RC version (e.g., '5.6.7RC1') or false $PHP_7_0_RC_DATE = '29 Sep 2016'; -$PHP_7_0_VERSION = "7.0.11"; -$PHP_7_0_DATE = "15 Sep 2016"; +$PHP_7_0_VERSION = "7.0.12"; +$PHP_7_0_DATE = "13 Oct 2016"; $PHP_7_0_MD5 = array( - "tar.bz2" => "daec0bee2e5cbec4b25535b9556f38bd", - "tar.gz" => "c2f285a11f05fe0f4f8a5d36a6814781", - "tar.xz" => "9a6013a5e9f258bbfb62ae5ac66b72da", + "tar.bz2" => "d7b11b40d84ed1f590e5f086f3711a3c", + "tar.gz" => "5dd00a65a1d76a4792f6989d4576623d", + "tar.xz" => "bdcc4dbdac90c2a39422786653059f70", ); $PHP_7_0_SHA256 = array( - "tar.bz2" => "f99b729dc1149858844b18af1e8c0de6dd1cdfdd52e22fbb4de2aa78bf9bf7f1", - "tar.gz" => "02d27b5d140dbad8d400a95af808e1e9ce87aa8d2a2100870734ba26e6700d79", - "tar.xz" => "d4cccea8da1d27c11b89386f8b8e95692ad3356610d571253d00ca67d524c735", -); + "tar.bz2" => "38c47294fe8fb239b0230dc63a93c3e4044f472ab93b5dff8b65feb4103a6a27", + "tar.gz" => "c4693cc363b4bbc7224294cc94faf3598e616cbe8540dd6975f68c7d3c52682f", + "tar.xz" => "f3d6c49e1c242e5995dec15e503fde996c327eb86cd7ec45c690e93c971b83ff", +; /* PHP 5.6 Release */ $PHP_5_6_RC = '5.6.27RC1'; // Current RC version (e.g., '5.6.7RC1') or false diff --git a/releases/7_0_12.php b/releases/7_0_12.php new file mode 100644 index 0000000..ea6c0f0 --- /dev/null +++ b/releases/7_0_12.php @@ -0,0 +1,22 @@ +<?php +// $Id$ +$_SERVER['BASE_PAGE'] = 'releases/7_0_12.php'; +include_once $_SERVER['DOCUMENT_ROOT'] . '/include/prepend.inc'; +site_header("PHP 7.0.12 Release Announcement"); +?> + + <h1>PHP 7.0.12 Release Announcement</h1> + + <p>The PHP development team announces the immediate availability of PHP + 7.0.12. This is a security release. Several security bugs were fixed in + this release. + + All PHP 7.0 users are encouraged to upgrade to this version. + </p> + + <p>For source downloads of PHP 7.0.12 please visit our <a href="http://www.php.net/downloads.php">downloads page</a>, + Windows source and binaries can be found on <a href="http://windows.php.net/download/">windows.php.net/download/</a>. + The list of changes is recorded in the <a href="http://www.php.net/ChangeLog-7.php#7.0.12">ChangeLog</a>. + </p> + +<?php site_footer(); ?>
« previous php.webmaster (#25236) next »