cvs: phpweb / ChangeLog-5.php /archive 2007.xml /include releases.inc version.inc /releases 5_2_5.php index.php
| From: | Ilia Alshanetsky | Date: | Fri, 09 Nov 2007 01:45:18 +0000 |
| Subject: | cvs: phpweb / ChangeLog-5.php /archive 2007.xml /include releases.inc version.inc /releases 5_2_5.php index.php | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-453@lists.php.net to get a copy of this message | ||
iliaa Fri Nov 9 01:45:18 2007 UTC
Added files:
/phpweb/releases 5_2_5.php
Modified files:
/phpweb ChangeLog-5.php
/phpweb/archive 2007.xml
/phpweb/include releases.inc version.inc
/phpweb/releases index.php
Log:
5.2.5
http://cvs.php.net/viewvc.cgi/phpweb/ChangeLog-5.php?r1=1.48&r2=1.49&diff_format=u Index: phpweb/ChangeLog-5.php diff -u phpweb/ChangeLog-5.php:1.48 phpweb/ChangeLog-5.php:1.49 --- phpweb/ChangeLog-5.php:1.48 Thu Aug 30 23:36:27 2007 +++ phpweb/ChangeLog-5.php Fri Nov 9 01:45:18 2007 @@ -1,5 +1,5 @@ <?php -// $Id: ChangeLog-5.php,v 1.48 2007/08/30 23:36:27 iliaa Exp $ +// $Id: ChangeLog-5.php,v 1.49 2007/11/09 01:45:18 iliaa Exp $ $_SERVER['BASE_PAGE'] = 'ChangeLog-5.php'; include_once $_SERVER['DOCUMENT_ROOT'] . '/include/prepend.inc'; site_header("PHP 5 ChangeLog"); @@ -11,6 +11,91 @@ <hr /> +<a name="5.2.5"></a> +<h3>Version 5.2.5</h3> +<b>08-November-2007</b> +<ul> + <li>Security Fixes + <ul> + <li>Fixed dl() to only accept filenames. reported by Laurent Gaffie.</li> + <li>Fixed dl() to limit argument size to MAXPATHLEN (CVE-2007-4887).</li> + <li>Fixed htmlentities/htmlspecialchars not to accept partial multibyte sequences.</li> + <li>Fixed possible triggering of buffer overflows inside glibc implementations of the fnmatch(), setlocale() and glob() functions. Reported by Laurent Gaffie.</li> + <li>Fixed "mail.force_extra_parameters" php.ini directive not to be modifiable in .htaccess due to the security implications reported by SecurityReason.</li> + <li><?php bugfix(42869); ?> (automatic session id insertion adds sessions id to non-local forms).</li> + <li><?php bugfix(41561); ?> (Values set with php_admin_* in httpd.conf can be overwritten with ini_set()).</li> + </ul> + </li> + +<li>Upgraded PCRE to version 7.3 (Nuno)</li> +<li>Added optional parameter $provide_object to debug_backtrace(). (Sebastian)</li> +<li>Added alpha support for imagefilter() IMG_FILTER_COLORIZE. (Pierre)</li> +<li>Added ability to control memory consumption between request using ZEND_MM_COMPACT environment variable. (Dmitry)</li> + +<li>Improved speed of array_intersect_key(), array_intersect_assoc(), array_uintersect_assoc(), array_diff_key(), array_diff_assoc() and array_udiff_assoc(). (Dmitry)</li> + +<li>Fixed move_uploaded_file() to always set file permissions of resulting file according to UMASK. (Andrew Sitnikov)</li> +<li>Fixed possible crash in ext/soap because of uninitialized value. (Zdash Urf)</li> +<li>Fixed regression in glob() when enforcing safe_mode/open_basedir checks on paths containing '*'. (Ilia)</li> +<li>Fixed PDO crash when driver returns empty LOB stream. (Stas)</li> +<li>Fixed iconv_*() functions to limit argument sizes as workaround to libc bug (CVE-2007-4783, CVE-2007-4840 by Laurent Gaffie). (Christian Hoffmann, Stas)</li> +<li>Fixed missing brackets leading to build warning and error in the log. Win32 code. (Andrey)</li> +<li>Fixed leaks with multiple connects on one mysqli object. (Andrey)</li> +<li>Fixed endianness detection on MacOS when building universal binary. (Uwe Schindler, Christian Speich, Tony)</li> +<li>Fixed imagerectangle regression with 1x1 rectangle (libgd #106). (Pierre)</li> + +<li><?php bugfix(43196); ?> (array_intersect_assoc() crashes with non-array input). (Jani)</li> +<li><?php bugfix(43139); ?> (PDO ignores ATTR_DEFAULT_FETCH_MODE in some cases with fetchAll()). (Ilia)</li> +<li><?php bugfix(43137); ?> (rmdir() and rename() do not clear statcache). (Jani)</li> +<li><?php bugfix(43130); ?> (Bound parameters cannot have - in their name). (Ilia)</li> +<li><?php bugfix(43099); ?> (XMLWriter::endElement() does not check # of params). (Ilia)</li> +<li><?php bugfix(43020); ?> (Warning message is missing with shuffle() and more than one argument). (Scott)</li> +<li><?php bugfix(42976); ?> (Crash when constructor for newInstance() or newInstanceArgs() fails) (Ilia)</li> +<li><?php bugfix(42943); ?> (ext/mssql: Move *timeout initialization from RINIT to connect time). (Ilia)</li> +<li><?php bugfix(42917); ?> (PDO::FETCH_KEY_PAIR doesn't work with setFetchMode). (Ilia)</li> +<li><?php bugfix(42890); ?> (Constant "LIST" defined by mysqlclient and c-client). (Andrey)</li> +<li><?php bugfix(42818); ?> ($foo = clone(array()); leaks memory). (Dmitry)</li> +<li><?php bugfix(42817); ?> (clone() on a non-object does not result in a fatal error). (Ilia)</li> +<li><?php bugfix(42785); ?> (json_encode() formats doubles according to locale rather then following standard syntax). (Ilia)</li> +<li><?php bugfix(42783); ?> (pg_insert() does not accept an empty list for insertion). (Ilia)</li> +<li><?php bugfix(42773); ?> (WSDL error causes HTTP 500 Response). (Dmitry)</li> +<li><?php bugfix(42772); ?> (Storing $this in a static var fails while handling a cast to string). (Dmitry)</li> +<li><?php bugfix(42767); ?> (highlight_string() truncates trailing comment). (Ilia)</li> +<li><?php bugfix(42739); ?> (mkdir() doesn't like a trailing slash when safe_mode is enabled). (Ilia)</li> +<li><?php bugfix(42703); ?> (Exception raised in an iterator::current() causes segfault in FilterIterator) (Marcus)</li> +<li><?php bugfix(42699); ?> (PHP_SELF duplicates path). (Dmitry)</li> +<li><?php bugfix(42654); ?> (RecursiveIteratorIterator modifies only part of leaves) (Marcus)</li> +<li><?php bugfix(42643); ?> (CLI segfaults if using ATTR_PERSISTENT). (Ilia)</li> +<li><?php bugfix(42637); ?> (SoapFault : Only http and https are allowed). (Bill Moran)</li> +<li><?php bugfix(42629); ?> (Dynamically loaded PHP extensions need symbols exported on MacOSX). (jdolecek at NetBSD dot org)</li> +<li><?php bugfix(42627); ?> (bz2 extension fails to build with -fno-common). (dolecek at netbsd dot org)</li> +<li><?php bugfix(42596); ?> (session.save_path MODE option does not work). (Ilia)</li> +<li><?php bugfix(42590); ?> (Make the engine recognize \v and \f escape sequences). (Ilia)</li> +<li><?php bugfix(42587); ?> (behavior change regarding symlinked .php files). (Dmitry)</li> +<li><?php bugfix(42579); ?> (apache_reset_timeout() does not exist). (Jani)</li> +<li><?php bugfix(42549); ?> (ext/mysql failed to compile with libmysql 3.23). (Scott)</li> +<li><?php bugfix(42523); ?> (PHP_SELF duplicates path). (Dmitry)</li> +<li><?php bugfix(42512); ?> (ip2long('255.255.255.255') should return 4294967295 on 64-bit PHP). (Derick)</li> +<li><?php bugfix(42506); ?> (php_pgsql_convert() timezone parse bug) (nonunnet at gmail dot com, Ilia)</li> +<li><?php bugfix(42462); ?> (Segmentation when trying to set an attribute in a DOMElement). (Rob)</li> +<li><?php bugfix(42453); ?> (CGI SAPI does not shut down cleanly with -i/-m/-v cmdline options). (Dmitry)</li> +<li><?php bugfix(42452); ?> (PDO classes do not expose Reflection API information). (Hannes)</li> +<li><?php bugfix(42468); ?> (Write lock on file_get_contents fails when using a compression stream). (Ilia)</li> +<li><?php bugfix(42488); ?> (SoapServer reports an encoding error and the error itself breaks). (Dmitry)</li> +<li><?php bugfix(42378); ?> (mysqli_stmt_bind_result memory exhaustion). (Andrey)</li> +<li><?php bugfix(42359); ?> (xsd:list type not parsed). (Dmitry)</li> +<li><?php bugfix(42326); ?> (SoapServer crash). (Dmitry)</li> +<li><?php bugfix(42214); ?> (SoapServer sends clients internal PHP errors). (Dmitry)</li> +<li><?php bugfix(42189); ?> (xmlrpc_set_type() crashes php on invalid datetime values). (Ilia)</li> +<li><?php bugfix(42139); ?> (XMLReader option constants are broken using XML()). (Rob)</li> +<li><?php bugfix(42086); ?> (SoapServer return Procedure '' not present for WSIBasic compliant wsdl). (Dmitry)</li> +<li><?php bugfix(41822); ?> (Relative includes broken when getcwd() fails). (Ab5602, Jani)</li> +<li><?php bugfix(39651); ?> (proc_open() append mode doesn't work on windows). (Nuno)</li> + +</ul> + +<hr /> + <a name="5.2.4"></a> <h3>Version 5.2.4</h3> <b>30-August-2007</b> http://cvs.php.net/viewvc.cgi/phpweb/archive/2007.xml?r1=1.25&r2=1.26&diff_format=u Index: phpweb/archive/2007.xml diff -u phpweb/archive/2007.xml:1.25 phpweb/archive/2007.xml:1.26 --- phpweb/archive/2007.xml:1.25 Tue Oct 30 01:28:24 2007 +++ phpweb/archive/2007.xml Fri Nov 9 01:45:18 2007 @@ -3,13 +3,26 @@ <title>PHP.net news & announcements</title> <link href="/feed.atom" rel="self"/> <icon>/images/news/php-logo.gif</icon> - <updated>2007-10-30T02:27:29+01:00</updated> + <updated>2007-11-08T19:33:04-05:00</updated> <id>http://php.net/archive/2007.php</id> <author> <name>Webmaster</name> <uri>http://php.net/contact</uri> <email>webmaster@php.net</email> </author> + <entry> + <title>PHP 5.2.5 Released</title> + <id>http://php.net/archive/2007.php#2007-11-08-1</id> + <published>2007-11-08T19:33:26-05:00</published> + <updated>2007-11-08T19:33:26-05:00</updated> + <category term="frontpage" label="PHP.net frontpage news"/> + <category term="releases" label="New PHP release"/> + <link href="/index.php#2007-11-08-1" rel="alternate" type="text/html"/> + <link href="/archive/2007.php#2007-11-08-1" rel="via" type="text/html"/> + <content type="xhtml"> + <div xmlns="http://www.w3.org/1999/xhtml"><p> The PHP development team would like to announce the immediate <a href="/downloads.php#v5">aavailability of PHP 5.2.5</a>. This release focuses on improving the stability of the PHP 5.2.x branch with over 60 bug fixes, several of which are security related. All users of PHP are encouraged to upgrade to this release.</p><p> Further details about the PHP 5.2.5 release can be found in the <a href="/releases/5_2_5.php">release announcement for 5.2.5</a>, the full list of changes is available in the <a href="/ChangeLog-5.php#5.2.5">ChangeLog for PHP 5</a>.</p><p> <b>Security Enhancements and Fixes in PHP 5.2.5:</b></p><ul> <li>Fixed dl() to only accept filenames. Reported by Laurent Gaffie.</li> <li>Fixed dl() to limit argument size to MAXPATHLEN (CVE-2007-4887). Reported by Laurent Gaffie.</li> <li>Fixed htmlentities/htmlspecialchars not to acce! pt partial multibyte sequences. Reported by Rasmus Lerdorf</li> <li>Fixed possible triggering of buffer overflows inside glibc implementations of the fnmatch(), setlocale() and glob() functions. Reported by Laurent Gaffie.</li> <li>Fixed "mail.force_extra_parameters" php.ini directive not to be modifiable in .htaccess due to the security implications. Reported by SecurityReason.</li> <li>Fixed bug #42869 (automatic session id insertion adds sessions id to non-local forms).</li> <li>Fixed bug #41561 (Values set with php_admin_* in httpd.conf can be overwritten with ini_set()).</li></ul><p>For users upgrading to PHP 5.2 from PHP 5.0 and PHP 5.1, an upgrade guide isavailable <a href="/migration52">here</a>, detailing the changes betweenthose releases and PHP 5.2.5.</p></div> + </content> + </entry> <entry xmlns="http://www.w3.org/2005/Atom"> <title>PHP Conference Brasil 2007</title> <link href="/conferences/index.php#2007-10-29-1" rel="alternate" type="text/html"/> @@ -39,7 +52,7 @@ <link href="/archive/2007.php#2007-10-03-1" rel="via" type="text/html"/> <content type="xhtml"> <div xmlns="http://www.w3.org/1999/xhtml"> - <p> + <p> The PHP documentation team is pleased to announce the initial release of the new build system that generates the PHP Manual. Written in PHP, PhD (<em>[PH]P based [D]ocBook renderer</em>) builds are now available for @@ -47,12 +60,12 @@ encouraged to test and use this system so that <a href="http://bugs.php.net/">bugs</a> will be found and squashed. </p> - <p> + <p> Once the new build system is stable, expect additional changes to the PHP manual that will include an improved navigation system and styling for OOP documentation. </p> - <p> + <p> Feel free to set this developmental mirror as your default by using <a href="/my.php">my.php</a>. </p> @@ -124,11 +137,7 @@ <div xmlns="http://www.w3.org/1999/xhtml"> <p> November 7th - 9th, Join us at the 2nd Annual DC PHP Conference. The event will take place at George Washington University's Cafritz Conference Center in the heart of Washington DC. The three day conference begins November 7th and 8th with general sessions, and ends November 9th with tutorials. This year's conference will host some of the PHP Community's top speakers and developers and focus on three primary tracks: -<ul> -<li>Scalability</li> -<li>Security</li> -<li>The Art of PHP</li> -</ul> +<ul><li>Scalability</li><li>Security</li><li>The Art of PHP</li></ul> Please see <a href="http://www.dcphpconference.com ">the website</a> for more details and to register. Early registration is available until mid-October. </p> </div> @@ -169,27 +178,25 @@ <php:newsImage link="http://conf.phpquebec.com/en" title="PHP Québec 2008">phpquebec.2008.png</php:newsImage> <content type="xhtml"> <div xmlns="http://www.w3.org/1999/xhtml"> -<p>PHP Quebec is pleased to announce the sixth edition of the <a -href="http://conf.phpquebec.com/en">PHP Quebec Conference</a>. The Conference + <p>PHP Quebec is pleased to announce the sixth edition of the <a href="http://conf.phpquebec.com/en">PHP Quebec Conference</a>. The Conference will take place in Montreal, Canada between March 12th and 14th, 2008. We are looking for speakers willing to share their expertise with Canadian and United States PHP professionals. </p> -<p> + <p> The Conference features the PHPLab, where speakers and visitors will find solutions to actual business problems. The two days of technical talks will be dedicated to advanced software development techniques with PHP5 and PHP6, XML, web services, databases, etc. </p> -<p> + <p> Organizers will prioritize new and original topics in English or French. -For more information, visit the website: <a -href="http://conf.phpquebec.com">http://conf.phpquebec.com</a> +For more information, visit the website: <a href="http://conf.phpquebec.com">http://conf.phpquebec.com</a> </p> </div> </content> </entry> -<entry xmlns="http://www.w3.org/2005/Atom"> + <entry xmlns="http://www.w3.org/2005/Atom"> <title>php|works 2007 in Atlanta</title> <link href="/conferences/index.php#2007-07-16-01" rel="alternate" type="text/html"/> <link href="http://works.phparch.com/" rel="via" type="text/html"/> http://cvs.php.net/viewvc.cgi/phpweb/include/releases.inc?r1=1.1&r2=1.2&diff_format=u Index: phpweb/include/releases.inc diff -u phpweb/include/releases.inc:1.1 phpweb/include/releases.inc:1.2 --- phpweb/include/releases.inc:1.1 Thu Sep 6 14:26:40 2007 +++ phpweb/include/releases.inc Fri Nov 9 01:45:18 2007 @@ -2,6 +2,45 @@ $OLDRELEASES = array ( 5 => array ( + '5.2.4' => + array ( + 'date' => '30 August 2007', + 'source' => + array ( + 0 => + array ( + 'filename' => 'php-5.2.4.tar.bz2', + 'name' => 'Source (tar.bz2)', + 'md5' => '55c97a671fdabf462cc7a82971a656d2', + ), + 1 => + array ( + 'filename' => 'php-5.2.4.tar.gz', + 'name' => 'Source (tar.gz)', + 'md5' => '0826e231c3148b29fd039d7a8c893ad3', + ), + ), + 'windows' => + array ( + 0 => + array ( + 'filename' => 'php-5.2.4-Win32.zip', + 'name' => 'Windows binary', + 'md5' => '979b8a305b028b296b97ed72322026b2', + ), + 1 => + array ( + 'filename' => 'pecl-5.2.4-Win32.zip', + 'name' => 'Collection of PECL modules for PHP 5.2.4', + 'md5' => 'dd98dfe607ceb98e727c394d5bd679fb', + ), + ), + 'announcement' => + array ( + 'English' => '/releases/5_2_4.php', + ), + 'museum' => false, + ), '5.2.3' => array ( 'date' => '31 May 2007', http://cvs.php.net/viewvc.cgi/phpweb/include/version.inc?r1=1.20&r2=1.21&diff_format=u Index: phpweb/include/version.inc diff -u phpweb/include/version.inc:1.20 phpweb/include/version.inc:1.21 --- phpweb/include/version.inc:1.20 Thu Nov 1 22:41:52 2007 +++ phpweb/include/version.inc Fri Nov 9 01:45:18 2007 @@ -17,19 +17,19 @@ */ /* PHP 5 Release */ -$PHP_5_VERSION = "5.2.4"; -$PHP_5_DATE = "30 August 2007"; +$PHP_5_VERSION = "5.2.5"; +$PHP_5_DATE = "08 November 2007"; $PHP_5_MD5 = array( - "tar.bz2" => "55c97a671fdabf462cc7a82971a656d2", - "tar.gz" => "0826e231c3148b29fd039d7a8c893ad3", - "zip" => "979b8a305b028b296b97ed72322026b2", - "installer" => "ad23dcc391a8c26c7d387eb5e9bf1ffb", - "pecl.zip" => "dd98dfe607ceb98e727c394d5bd679fb", - "nts.zip" => "7728b869cfe3b8b7f1751da0a298fc12", - "pecl.nts" => "44302972cffd2b9cf05cb7131b56056a", + "tar.bz2" => "61a0e1661b70760acc77bc4841900b7a", + "tar.gz" => "61a0e1661b70760acc77bc4841900b7a", + "zip" => "", + "installer" => "", + "pecl.zip" => "", + "nts.zip" => "", + "pecl.nts" => "", ); -$PHP_5_RC = "5.2.5RC2"; +$PHP_5_RC = false; $PHP_5_RC_DATE = "01 November 2007"; /* PHP 4 Release */ @@ -62,7 +62,7 @@ "date" => $PHP_5_DATE, ), ), - "windows" => array( /* Prefix the key with dot if the windows stuff isn't available yet*/ + ".windows" => array( /* Prefix the key with dot if the windows stuff isn't available yet*/ array( "filename" => "php-$PHP_5_VERSION-Win32.zip", "name" => "PHP $PHP_5_VERSION zip package", @@ -86,7 +86,7 @@ "name" => "PHP $PHP_5_VERSION Non-thread-safe Win32 binaries", "md5" => $PHP_5_MD5["nts.zip"], "date" => $PHP_5_DATE, - ), + ), array( "filename" => "pecl-$PHP_5_VERSION-nts-Win32.zip", "name" => "PECL $PHP_5_VERSION Non-thread-safe Win32 binaries", http://cvs.php.net/viewvc.cgi/phpweb/releases/index.php?r1=1.17&r2=1.18&diff_format=u Index: phpweb/releases/index.php diff -u phpweb/releases/index.php:1.17 phpweb/releases/index.php:1.18 --- phpweb/releases/index.php:1.17 Fri Sep 7 11:57:02 2007 +++ phpweb/releases/index.php Fri Nov 9 01:45:18 2007 @@ -1,5 +1,5 @@ <?php -// $Id: index.php,v 1.17 2007/09/07 11:57:02 bjori Exp $ +// $Id: index.php,v 1.18 2007/11/09 01:45:18 iliaa Exp $ $_SERVER['BASE_PAGE'] = 'releases/index.php'; include_once $_SERVER['DOCUMENT_ROOT'] . '/include/prepend.inc'; include_once $_SERVER["DOCUMENT_ROOT"] . "/include/releases.inc"; @@ -145,6 +145,7 @@ <option value="php-5.2.1.tar.gz">5.2.1</option> <option value="php-5.2.2.tar.gz">5.2.2</option> <option value="php-5.2.3.tar.gz">5.2.3</option> + <option value="php-5.2.4.tar.gz">5.2.4</option> </select> </p> </form> http://cvs.php.net/viewvc.cgi/phpweb/releases/5_2_5.php?view=markup&rev=1.1 Index: phpweb/releases/5_2_5.php +++ phpweb/releases/5_2_5.php <?php // $Id: 5_2_5.php,v 1.1 2007/11/09 01:45:18 iliaa Exp $ $_SERVER['BASE_PAGE'] = 'releases/5_2_5.php'; include_once $_SERVER['DOCUMENT_ROOT'] . '/include/prepend.inc'; site_header("PHP 5.2.5 Release Announcement"); ?> <h1>PHP 5.2.5 Release Announcement</h1> <p> The PHP development team would like to announce the immediate availability of PHP 5.2.5. This release focuses on improving the stability of the PHP 5.2.x branch with over 60 bug fixes, several of which are security related. All users of PHP are encouraged to upgrade to this release. </p> <p> <b>Security Enhancements and Fixes in PHP 5.2.5:</b> </p> <ul> <li>Fixed dl() to only accept filenames. Reported by Laurent Gaffie.</li> <li>Fixed dl() to limit argument size to MAXPATHLEN (CVE-2007-4887). Reported by Laurent Gaffie.</li> <li>Fixed htmlentities/htmlspecialchars not to accept partial multibyte sequences. Reported by Rasmus Lerdorf</li> <li>Fixed possible triggering of buffer overflows inside glibc implementations of the fnmatch(), setlocale() and glob() functions. Reported by Laurent Gaffie.</li> <li>Fixed "mail.force_extra_parameters" php.ini directive not to be modifiable in .htaccess due to the security implications. Reported by SecurityReason.</li> <li>Fixed bug #42869 (automatic session id insertion adds sessions id to non-local forms).</li> <li>Fixed bug #41561 (Values set with php_admin_* in httpd.conf can be overwritten with ini_set()).</li> </ul> <p> <b>Key enhancements in PHP 5.2.5 include:</b> </p> <ul> <li>Upgraded PCRE to version 7.3</li> <li>Updated timezone database to version 2007.9</li> <li>Added ability to control memory consumption between request using ZEND_MM_COMPACT environment variable.</li> <li>Improved speed of array_intersect_key(), array_intersect_assoc(), array_uintersect_assoc(), array_diff_key(), array_diff_assoc() and array_udiff_assoc() functions</li> <li>Fixed bug #43139 (PDO ignores ATTR_DEFAULT_FETCH_MODE in some cases with fetchAll())</li> <li>Fixed bug #42785 (json_encode() formats doubles according to locale rather then following standard syntax)</li> <li>Fixed bug #42549 (ext/mysql failed to compile with libmysql 3.23)</li> <li>Over 60 bug fixes.</li> </ul> <p> For users upgrading from PHP 5.0 and PHP 5.1, an upgrade guide is available <a href="/UPDATE_5_2.txt">here</a>, detailing the changes between those releases and PHP 5.2.5. </p> <p> For a full list of changes in PHP 5.2.5, see the <a href="/ChangeLog-5.php#5.2.5">ChangeLog</a>. </p> <?php site_footer(); ?>
http://cvs.php.net/viewvc.cgi/phpweb/ChangeLog-5.php?r1=1.48&r2=1.49&diff_format=u Index: phpweb/ChangeLog-5.php diff -u phpweb/ChangeLog-5.php:1.48 phpweb/ChangeLog-5.php:1.49 --- phpweb/ChangeLog-5.php:1.48 Thu Aug 30 23:36:27 2007 +++ phpweb/ChangeLog-5.php Fri Nov 9 01:45:18 2007 @@ -1,5 +1,5 @@ <?php -// $Id: ChangeLog-5.php,v 1.48 2007/08/30 23:36:27 iliaa Exp $ +// $Id: ChangeLog-5.php,v 1.49 2007/11/09 01:45:18 iliaa Exp $ $_SERVER['BASE_PAGE'] = 'ChangeLog-5.php'; include_once $_SERVER['DOCUMENT_ROOT'] . '/include/prepend.inc'; site_header("PHP 5 ChangeLog"); @@ -11,6 +11,91 @@ <hr /> +<a name="5.2.5"></a> +<h3>Version 5.2.5</h3> +<b>08-November-2007</b> +<ul> + <li>Security Fixes + <ul> + <li>Fixed dl() to only accept filenames. reported by Laurent Gaffie.</li> + <li>Fixed dl() to limit argument size to MAXPATHLEN (CVE-2007-4887).</li> + <li>Fixed htmlentities/htmlspecialchars not to accept partial multibyte sequences.</li> + <li>Fixed possible triggering of buffer overflows inside glibc implementations of the fnmatch(), setlocale() and glob() functions. Reported by Laurent Gaffie.</li> + <li>Fixed "mail.force_extra_parameters" php.ini directive not to be modifiable in .htaccess due to the security implications reported by SecurityReason.</li> + <li><?php bugfix(42869); ?> (automatic session id insertion adds sessions id to non-local forms).</li> + <li><?php bugfix(41561); ?> (Values set with php_admin_* in httpd.conf can be overwritten with ini_set()).</li> + </ul> + </li> + +<li>Upgraded PCRE to version 7.3 (Nuno)</li> +<li>Added optional parameter $provide_object to debug_backtrace(). (Sebastian)</li> +<li>Added alpha support for imagefilter() IMG_FILTER_COLORIZE. (Pierre)</li> +<li>Added ability to control memory consumption between request using ZEND_MM_COMPACT environment variable. (Dmitry)</li> + +<li>Improved speed of array_intersect_key(), array_intersect_assoc(), array_uintersect_assoc(), array_diff_key(), array_diff_assoc() and array_udiff_assoc(). (Dmitry)</li> + +<li>Fixed move_uploaded_file() to always set file permissions of resulting file according to UMASK. (Andrew Sitnikov)</li> +<li>Fixed possible crash in ext/soap because of uninitialized value. (Zdash Urf)</li> +<li>Fixed regression in glob() when enforcing safe_mode/open_basedir checks on paths containing '*'. (Ilia)</li> +<li>Fixed PDO crash when driver returns empty LOB stream. (Stas)</li> +<li>Fixed iconv_*() functions to limit argument sizes as workaround to libc bug (CVE-2007-4783, CVE-2007-4840 by Laurent Gaffie). (Christian Hoffmann, Stas)</li> +<li>Fixed missing brackets leading to build warning and error in the log. Win32 code. (Andrey)</li> +<li>Fixed leaks with multiple connects on one mysqli object. (Andrey)</li> +<li>Fixed endianness detection on MacOS when building universal binary. (Uwe Schindler, Christian Speich, Tony)</li> +<li>Fixed imagerectangle regression with 1x1 rectangle (libgd #106). (Pierre)</li> + +<li><?php bugfix(43196); ?> (array_intersect_assoc() crashes with non-array input). (Jani)</li> +<li><?php bugfix(43139); ?> (PDO ignores ATTR_DEFAULT_FETCH_MODE in some cases with fetchAll()). (Ilia)</li> +<li><?php bugfix(43137); ?> (rmdir() and rename() do not clear statcache). (Jani)</li> +<li><?php bugfix(43130); ?> (Bound parameters cannot have - in their name). (Ilia)</li> +<li><?php bugfix(43099); ?> (XMLWriter::endElement() does not check # of params). (Ilia)</li> +<li><?php bugfix(43020); ?> (Warning message is missing with shuffle() and more than one argument). (Scott)</li> +<li><?php bugfix(42976); ?> (Crash when constructor for newInstance() or newInstanceArgs() fails) (Ilia)</li> +<li><?php bugfix(42943); ?> (ext/mssql: Move *timeout initialization from RINIT to connect time). (Ilia)</li> +<li><?php bugfix(42917); ?> (PDO::FETCH_KEY_PAIR doesn't work with setFetchMode). (Ilia)</li> +<li><?php bugfix(42890); ?> (Constant "LIST" defined by mysqlclient and c-client). (Andrey)</li> +<li><?php bugfix(42818); ?> ($foo = clone(array()); leaks memory). (Dmitry)</li> +<li><?php bugfix(42817); ?> (clone() on a non-object does not result in a fatal error). (Ilia)</li> +<li><?php bugfix(42785); ?> (json_encode() formats doubles according to locale rather then following standard syntax). (Ilia)</li> +<li><?php bugfix(42783); ?> (pg_insert() does not accept an empty list for insertion). (Ilia)</li> +<li><?php bugfix(42773); ?> (WSDL error causes HTTP 500 Response). (Dmitry)</li> +<li><?php bugfix(42772); ?> (Storing $this in a static var fails while handling a cast to string). (Dmitry)</li> +<li><?php bugfix(42767); ?> (highlight_string() truncates trailing comment). (Ilia)</li> +<li><?php bugfix(42739); ?> (mkdir() doesn't like a trailing slash when safe_mode is enabled). (Ilia)</li> +<li><?php bugfix(42703); ?> (Exception raised in an iterator::current() causes segfault in FilterIterator) (Marcus)</li> +<li><?php bugfix(42699); ?> (PHP_SELF duplicates path). (Dmitry)</li> +<li><?php bugfix(42654); ?> (RecursiveIteratorIterator modifies only part of leaves) (Marcus)</li> +<li><?php bugfix(42643); ?> (CLI segfaults if using ATTR_PERSISTENT). (Ilia)</li> +<li><?php bugfix(42637); ?> (SoapFault : Only http and https are allowed). (Bill Moran)</li> +<li><?php bugfix(42629); ?> (Dynamically loaded PHP extensions need symbols exported on MacOSX). (jdolecek at NetBSD dot org)</li> +<li><?php bugfix(42627); ?> (bz2 extension fails to build with -fno-common). (dolecek at netbsd dot org)</li> +<li><?php bugfix(42596); ?> (session.save_path MODE option does not work). (Ilia)</li> +<li><?php bugfix(42590); ?> (Make the engine recognize \v and \f escape sequences). (Ilia)</li> +<li><?php bugfix(42587); ?> (behavior change regarding symlinked .php files). (Dmitry)</li> +<li><?php bugfix(42579); ?> (apache_reset_timeout() does not exist). (Jani)</li> +<li><?php bugfix(42549); ?> (ext/mysql failed to compile with libmysql 3.23). (Scott)</li> +<li><?php bugfix(42523); ?> (PHP_SELF duplicates path). (Dmitry)</li> +<li><?php bugfix(42512); ?> (ip2long('255.255.255.255') should return 4294967295 on 64-bit PHP). (Derick)</li> +<li><?php bugfix(42506); ?> (php_pgsql_convert() timezone parse bug) (nonunnet at gmail dot com, Ilia)</li> +<li><?php bugfix(42462); ?> (Segmentation when trying to set an attribute in a DOMElement). (Rob)</li> +<li><?php bugfix(42453); ?> (CGI SAPI does not shut down cleanly with -i/-m/-v cmdline options). (Dmitry)</li> +<li><?php bugfix(42452); ?> (PDO classes do not expose Reflection API information). (Hannes)</li> +<li><?php bugfix(42468); ?> (Write lock on file_get_contents fails when using a compression stream). (Ilia)</li> +<li><?php bugfix(42488); ?> (SoapServer reports an encoding error and the error itself breaks). (Dmitry)</li> +<li><?php bugfix(42378); ?> (mysqli_stmt_bind_result memory exhaustion). (Andrey)</li> +<li><?php bugfix(42359); ?> (xsd:list type not parsed). (Dmitry)</li> +<li><?php bugfix(42326); ?> (SoapServer crash). (Dmitry)</li> +<li><?php bugfix(42214); ?> (SoapServer sends clients internal PHP errors). (Dmitry)</li> +<li><?php bugfix(42189); ?> (xmlrpc_set_type() crashes php on invalid datetime values). (Ilia)</li> +<li><?php bugfix(42139); ?> (XMLReader option constants are broken using XML()). (Rob)</li> +<li><?php bugfix(42086); ?> (SoapServer return Procedure '' not present for WSIBasic compliant wsdl). (Dmitry)</li> +<li><?php bugfix(41822); ?> (Relative includes broken when getcwd() fails). (Ab5602, Jani)</li> +<li><?php bugfix(39651); ?> (proc_open() append mode doesn't work on windows). (Nuno)</li> + +</ul> + +<hr /> + <a name="5.2.4"></a> <h3>Version 5.2.4</h3> <b>30-August-2007</b> http://cvs.php.net/viewvc.cgi/phpweb/archive/2007.xml?r1=1.25&r2=1.26&diff_format=u Index: phpweb/archive/2007.xml diff -u phpweb/archive/2007.xml:1.25 phpweb/archive/2007.xml:1.26 --- phpweb/archive/2007.xml:1.25 Tue Oct 30 01:28:24 2007 +++ phpweb/archive/2007.xml Fri Nov 9 01:45:18 2007 @@ -3,13 +3,26 @@ <title>PHP.net news & announcements</title> <link href="/feed.atom" rel="self"/> <icon>/images/news/php-logo.gif</icon> - <updated>2007-10-30T02:27:29+01:00</updated> + <updated>2007-11-08T19:33:04-05:00</updated> <id>http://php.net/archive/2007.php</id> <author> <name>Webmaster</name> <uri>http://php.net/contact</uri> <email>webmaster@php.net</email> </author> + <entry> + <title>PHP 5.2.5 Released</title> + <id>http://php.net/archive/2007.php#2007-11-08-1</id> + <published>2007-11-08T19:33:26-05:00</published> + <updated>2007-11-08T19:33:26-05:00</updated> + <category term="frontpage" label="PHP.net frontpage news"/> + <category term="releases" label="New PHP release"/> + <link href="/index.php#2007-11-08-1" rel="alternate" type="text/html"/> + <link href="/archive/2007.php#2007-11-08-1" rel="via" type="text/html"/> + <content type="xhtml"> + <div xmlns="http://www.w3.org/1999/xhtml"><p> The PHP development team would like to announce the immediate <a href="/downloads.php#v5">aavailability of PHP 5.2.5</a>. This release focuses on improving the stability of the PHP 5.2.x branch with over 60 bug fixes, several of which are security related. All users of PHP are encouraged to upgrade to this release.</p><p> Further details about the PHP 5.2.5 release can be found in the <a href="/releases/5_2_5.php">release announcement for 5.2.5</a>, the full list of changes is available in the <a href="/ChangeLog-5.php#5.2.5">ChangeLog for PHP 5</a>.</p><p> <b>Security Enhancements and Fixes in PHP 5.2.5:</b></p><ul> <li>Fixed dl() to only accept filenames. Reported by Laurent Gaffie.</li> <li>Fixed dl() to limit argument size to MAXPATHLEN (CVE-2007-4887). Reported by Laurent Gaffie.</li> <li>Fixed htmlentities/htmlspecialchars not to acce! pt partial multibyte sequences. Reported by Rasmus Lerdorf</li> <li>Fixed possible triggering of buffer overflows inside glibc implementations of the fnmatch(), setlocale() and glob() functions. Reported by Laurent Gaffie.</li> <li>Fixed "mail.force_extra_parameters" php.ini directive not to be modifiable in .htaccess due to the security implications. Reported by SecurityReason.</li> <li>Fixed bug #42869 (automatic session id insertion adds sessions id to non-local forms).</li> <li>Fixed bug #41561 (Values set with php_admin_* in httpd.conf can be overwritten with ini_set()).</li></ul><p>For users upgrading to PHP 5.2 from PHP 5.0 and PHP 5.1, an upgrade guide isavailable <a href="/migration52">here</a>, detailing the changes betweenthose releases and PHP 5.2.5.</p></div> + </content> + </entry> <entry xmlns="http://www.w3.org/2005/Atom"> <title>PHP Conference Brasil 2007</title> <link href="/conferences/index.php#2007-10-29-1" rel="alternate" type="text/html"/> @@ -39,7 +52,7 @@ <link href="/archive/2007.php#2007-10-03-1" rel="via" type="text/html"/> <content type="xhtml"> <div xmlns="http://www.w3.org/1999/xhtml"> - <p> + <p> The PHP documentation team is pleased to announce the initial release of the new build system that generates the PHP Manual. Written in PHP, PhD (<em>[PH]P based [D]ocBook renderer</em>) builds are now available for @@ -47,12 +60,12 @@ encouraged to test and use this system so that <a href="http://bugs.php.net/">bugs</a> will be found and squashed. </p> - <p> + <p> Once the new build system is stable, expect additional changes to the PHP manual that will include an improved navigation system and styling for OOP documentation. </p> - <p> + <p> Feel free to set this developmental mirror as your default by using <a href="/my.php">my.php</a>. </p> @@ -124,11 +137,7 @@ <div xmlns="http://www.w3.org/1999/xhtml"> <p> November 7th - 9th, Join us at the 2nd Annual DC PHP Conference. The event will take place at George Washington University's Cafritz Conference Center in the heart of Washington DC. The three day conference begins November 7th and 8th with general sessions, and ends November 9th with tutorials. This year's conference will host some of the PHP Community's top speakers and developers and focus on three primary tracks: -<ul> -<li>Scalability</li> -<li>Security</li> -<li>The Art of PHP</li> -</ul> +<ul><li>Scalability</li><li>Security</li><li>The Art of PHP</li></ul> Please see <a href="http://www.dcphpconference.com ">the website</a> for more details and to register. Early registration is available until mid-October. </p> </div> @@ -169,27 +178,25 @@ <php:newsImage link="http://conf.phpquebec.com/en" title="PHP Québec 2008">phpquebec.2008.png</php:newsImage> <content type="xhtml"> <div xmlns="http://www.w3.org/1999/xhtml"> -<p>PHP Quebec is pleased to announce the sixth edition of the <a -href="http://conf.phpquebec.com/en">PHP Quebec Conference</a>. The Conference + <p>PHP Quebec is pleased to announce the sixth edition of the <a href="http://conf.phpquebec.com/en">PHP Quebec Conference</a>. The Conference will take place in Montreal, Canada between March 12th and 14th, 2008. We are looking for speakers willing to share their expertise with Canadian and United States PHP professionals. </p> -<p> + <p> The Conference features the PHPLab, where speakers and visitors will find solutions to actual business problems. The two days of technical talks will be dedicated to advanced software development techniques with PHP5 and PHP6, XML, web services, databases, etc. </p> -<p> + <p> Organizers will prioritize new and original topics in English or French. -For more information, visit the website: <a -href="http://conf.phpquebec.com">http://conf.phpquebec.com</a> +For more information, visit the website: <a href="http://conf.phpquebec.com">http://conf.phpquebec.com</a> </p> </div> </content> </entry> -<entry xmlns="http://www.w3.org/2005/Atom"> + <entry xmlns="http://www.w3.org/2005/Atom"> <title>php|works 2007 in Atlanta</title> <link href="/conferences/index.php#2007-07-16-01" rel="alternate" type="text/html"/> <link href="http://works.phparch.com/" rel="via" type="text/html"/> http://cvs.php.net/viewvc.cgi/phpweb/include/releases.inc?r1=1.1&r2=1.2&diff_format=u Index: phpweb/include/releases.inc diff -u phpweb/include/releases.inc:1.1 phpweb/include/releases.inc:1.2 --- phpweb/include/releases.inc:1.1 Thu Sep 6 14:26:40 2007 +++ phpweb/include/releases.inc Fri Nov 9 01:45:18 2007 @@ -2,6 +2,45 @@ $OLDRELEASES = array ( 5 => array ( + '5.2.4' => + array ( + 'date' => '30 August 2007', + 'source' => + array ( + 0 => + array ( + 'filename' => 'php-5.2.4.tar.bz2', + 'name' => 'Source (tar.bz2)', + 'md5' => '55c97a671fdabf462cc7a82971a656d2', + ), + 1 => + array ( + 'filename' => 'php-5.2.4.tar.gz', + 'name' => 'Source (tar.gz)', + 'md5' => '0826e231c3148b29fd039d7a8c893ad3', + ), + ), + 'windows' => + array ( + 0 => + array ( + 'filename' => 'php-5.2.4-Win32.zip', + 'name' => 'Windows binary', + 'md5' => '979b8a305b028b296b97ed72322026b2', + ), + 1 => + array ( + 'filename' => 'pecl-5.2.4-Win32.zip', + 'name' => 'Collection of PECL modules for PHP 5.2.4', + 'md5' => 'dd98dfe607ceb98e727c394d5bd679fb', + ), + ), + 'announcement' => + array ( + 'English' => '/releases/5_2_4.php', + ), + 'museum' => false, + ), '5.2.3' => array ( 'date' => '31 May 2007', http://cvs.php.net/viewvc.cgi/phpweb/include/version.inc?r1=1.20&r2=1.21&diff_format=u Index: phpweb/include/version.inc diff -u phpweb/include/version.inc:1.20 phpweb/include/version.inc:1.21 --- phpweb/include/version.inc:1.20 Thu Nov 1 22:41:52 2007 +++ phpweb/include/version.inc Fri Nov 9 01:45:18 2007 @@ -17,19 +17,19 @@ */ /* PHP 5 Release */ -$PHP_5_VERSION = "5.2.4"; -$PHP_5_DATE = "30 August 2007"; +$PHP_5_VERSION = "5.2.5"; +$PHP_5_DATE = "08 November 2007"; $PHP_5_MD5 = array( - "tar.bz2" => "55c97a671fdabf462cc7a82971a656d2", - "tar.gz" => "0826e231c3148b29fd039d7a8c893ad3", - "zip" => "979b8a305b028b296b97ed72322026b2", - "installer" => "ad23dcc391a8c26c7d387eb5e9bf1ffb", - "pecl.zip" => "dd98dfe607ceb98e727c394d5bd679fb", - "nts.zip" => "7728b869cfe3b8b7f1751da0a298fc12", - "pecl.nts" => "44302972cffd2b9cf05cb7131b56056a", + "tar.bz2" => "61a0e1661b70760acc77bc4841900b7a", + "tar.gz" => "61a0e1661b70760acc77bc4841900b7a", + "zip" => "", + "installer" => "", + "pecl.zip" => "", + "nts.zip" => "", + "pecl.nts" => "", ); -$PHP_5_RC = "5.2.5RC2"; +$PHP_5_RC = false; $PHP_5_RC_DATE = "01 November 2007"; /* PHP 4 Release */ @@ -62,7 +62,7 @@ "date" => $PHP_5_DATE, ), ), - "windows" => array( /* Prefix the key with dot if the windows stuff isn't available yet*/ + ".windows" => array( /* Prefix the key with dot if the windows stuff isn't available yet*/ array( "filename" => "php-$PHP_5_VERSION-Win32.zip", "name" => "PHP $PHP_5_VERSION zip package", @@ -86,7 +86,7 @@ "name" => "PHP $PHP_5_VERSION Non-thread-safe Win32 binaries", "md5" => $PHP_5_MD5["nts.zip"], "date" => $PHP_5_DATE, - ), + ), array( "filename" => "pecl-$PHP_5_VERSION-nts-Win32.zip", "name" => "PECL $PHP_5_VERSION Non-thread-safe Win32 binaries", http://cvs.php.net/viewvc.cgi/phpweb/releases/index.php?r1=1.17&r2=1.18&diff_format=u Index: phpweb/releases/index.php diff -u phpweb/releases/index.php:1.17 phpweb/releases/index.php:1.18 --- phpweb/releases/index.php:1.17 Fri Sep 7 11:57:02 2007 +++ phpweb/releases/index.php Fri Nov 9 01:45:18 2007 @@ -1,5 +1,5 @@ <?php -// $Id: index.php,v 1.17 2007/09/07 11:57:02 bjori Exp $ +// $Id: index.php,v 1.18 2007/11/09 01:45:18 iliaa Exp $ $_SERVER['BASE_PAGE'] = 'releases/index.php'; include_once $_SERVER['DOCUMENT_ROOT'] . '/include/prepend.inc'; include_once $_SERVER["DOCUMENT_ROOT"] . "/include/releases.inc"; @@ -145,6 +145,7 @@ <option value="php-5.2.1.tar.gz">5.2.1</option> <option value="php-5.2.2.tar.gz">5.2.2</option> <option value="php-5.2.3.tar.gz">5.2.3</option> + <option value="php-5.2.4.tar.gz">5.2.4</option> </select> </p> </form> http://cvs.php.net/viewvc.cgi/phpweb/releases/5_2_5.php?view=markup&rev=1.1 Index: phpweb/releases/5_2_5.php +++ phpweb/releases/5_2_5.php <?php // $Id: 5_2_5.php,v 1.1 2007/11/09 01:45:18 iliaa Exp $ $_SERVER['BASE_PAGE'] = 'releases/5_2_5.php'; include_once $_SERVER['DOCUMENT_ROOT'] . '/include/prepend.inc'; site_header("PHP 5.2.5 Release Announcement"); ?> <h1>PHP 5.2.5 Release Announcement</h1> <p> The PHP development team would like to announce the immediate availability of PHP 5.2.5. This release focuses on improving the stability of the PHP 5.2.x branch with over 60 bug fixes, several of which are security related. All users of PHP are encouraged to upgrade to this release. </p> <p> <b>Security Enhancements and Fixes in PHP 5.2.5:</b> </p> <ul> <li>Fixed dl() to only accept filenames. Reported by Laurent Gaffie.</li> <li>Fixed dl() to limit argument size to MAXPATHLEN (CVE-2007-4887). Reported by Laurent Gaffie.</li> <li>Fixed htmlentities/htmlspecialchars not to accept partial multibyte sequences. Reported by Rasmus Lerdorf</li> <li>Fixed possible triggering of buffer overflows inside glibc implementations of the fnmatch(), setlocale() and glob() functions. Reported by Laurent Gaffie.</li> <li>Fixed "mail.force_extra_parameters" php.ini directive not to be modifiable in .htaccess due to the security implications. Reported by SecurityReason.</li> <li>Fixed bug #42869 (automatic session id insertion adds sessions id to non-local forms).</li> <li>Fixed bug #41561 (Values set with php_admin_* in httpd.conf can be overwritten with ini_set()).</li> </ul> <p> <b>Key enhancements in PHP 5.2.5 include:</b> </p> <ul> <li>Upgraded PCRE to version 7.3</li> <li>Updated timezone database to version 2007.9</li> <li>Added ability to control memory consumption between request using ZEND_MM_COMPACT environment variable.</li> <li>Improved speed of array_intersect_key(), array_intersect_assoc(), array_uintersect_assoc(), array_diff_key(), array_diff_assoc() and array_udiff_assoc() functions</li> <li>Fixed bug #43139 (PDO ignores ATTR_DEFAULT_FETCH_MODE in some cases with fetchAll())</li> <li>Fixed bug #42785 (json_encode() formats doubles according to locale rather then following standard syntax)</li> <li>Fixed bug #42549 (ext/mysql failed to compile with libmysql 3.23)</li> <li>Over 60 bug fixes.</li> </ul> <p> For users upgrading from PHP 5.0 and PHP 5.1, an upgrade guide is available <a href="/UPDATE_5_2.txt">here</a>, detailing the changes between those releases and PHP 5.2.5. </p> <p> For a full list of changes in PHP 5.2.5, see the <a href="/ChangeLog-5.php#5.2.5">ChangeLog</a>. </p> <?php site_footer(); ?>