svn: /web/php/trunk/releases/ 5_2_14.php 5_3_3.php

From: Date: Thu, 22 Jul 2010 10:55:24 +0000
Subject: svn: /web/php/trunk/releases/ 5_2_14.php 5_3_3.php
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-8567@lists.php.net to get a copy of this message
johannes Thu, 22 Jul 2010 10:55:24 +0000 Revision: http://svn.php.net/viewvc?view=revision&revision=301462 Log: - Add Release announcements for PHP 5.2.14 and 5.3.3 Changed paths: A web/php/trunk/releases/5_2_14.php A web/php/trunk/releases/5_3_3.php Added: web/php/trunk/releases/5_2_14.php =================================================================== --- web/php/trunk/releases/5_2_14.php (rev 0) +++ web/php/trunk/releases/5_2_14.php 2010-07-22 10:55:24 UTC (rev 301462) @@ -0,0 +1,66 @@ +<?php +// $Id $ +$_SERVER['BASE_PAGE'] = 'releases/5_2_14.php'; +include_once $_SERVER['DOCUMENT_ROOT'] . '/include/prepend.inc'; +site_header("PHP 5.2.14 Release Announcement"); +?> + +<h1>PHP 5.2.14 Release Announcement</h1> +<p> +The PHP development team would like to announce the immediate +availability of PHP 5.2.14. This release focuses on improving the +stability of the PHP 5.2.x branch with over 60 bug fixes, some of which +are security related.</p> + +<p> +This release marks the end of the active support for PHP +5.2. Following this release the PHP 5.2 series will receive no further +active bug maintenance. Security fixes for PHP 5.2 might be published on a +case by cases basis. All users of PHP 5.2 are encouraged to upgrade to +PHP 5.3.</p> + +<p> +<b>Security Enhancements and Fixes in PHP 5.2.14:</b> +</p> +<ul> + + <li>Rewrote var_export() to use smart_str rather than output buffering, prevents data disclosure if a fatal error occurs.</li> + <li>Fixed a possible interruption array leak in strrchr().(CVE-2010-2484)</li> + <li>Fixed a possible interruption array leak in strchr(), strstr(), substr(), chunk_split(), strtok(), addcslashes(), str_repeat(), trim().</li> + <li>Fixed a possible memory corruption in substr_replace().</li> + <li>Fixed SplObjectStorage unserialization problems (CVE-2010-2225).</li> + <li>Fixed a possible stack exaustion inside fnmatch().</li> + <li>Fixed a NULL pointer dereference when processing invalid XML-RPC requests (Fixes CVE-2010-0397, bug #51288).</li> + <li>Fixed handling of session variable serialization on certain prefix characters.</li> + <li>Fixed a possible arbitrary memory access inside sqlite extension. Reported by Mateusz Kocielski.</li> +</ul> + +<p> +<b>Key enhancements in PHP 5.2.14 include:</b> +</p> +<ul> + + <li>Upgraded bundled PCRE to version 8.02.</li> + <li>Updated timezone database to version 2010.5.</li> + <li>Fixed bug #52238 (Crash when an Exception occured in iterator_to_array).</li> + <li>Fixed bug #52237 (Crash when passing the reference of the property of a non-object).</li> + <li>Fixed bug #52041 (Memory leak when writing on uninitialized variable returned from function).</li> + <li>Fixed bug #51822 (Segfault with strange __destruct() for static class variables).</li> + <li>Fixed bug #51552 (debug_backtrace() causes segmentation fault and/or memory issues).</li> + <li>Fixed bug #49267 (Linking fails for iconv on MacOS: "Undefined symbols: _libiconv").</li> +</ul> + +<p>To prepare upgrading to PHP 5.3, now that PHP 5.2's support ended, mind +the migration guide available on <http://php.net/migration53>, detailing +the changes between PHP 5.2 and PHP 5.3.</p> + +<p>For a full list of changes in PHP 5.2.14, see the ChangeLog at +<http://www.php.net/ChangeLog-5.php#5.2.14>.</p> + + +<p>To prepare for upgrading to PHP 5.3, now that PHP 5.2's support has ended, a migration guide available on <a +href="http://php.net/migration53">http://php.net/migration53</a>, details the changes between PHP 5.2 and PHP 5.3.</p> + +<p>For a full list of changes in PHP 5.2.14 see the ChangeLog at <a href="http://www.php.net/ChangeLog-5.php#5.2.14">http://www.php.net/ChangeLog-5.php#5.2.14</a>.</p> + +<?php site_footer(); ?> Added: web/php/trunk/releases/5_3_3.php =================================================================== --- web/php/trunk/releases/5_3_3.php (rev 0) +++ web/php/trunk/releases/5_3_3.php 2010-07-22 10:55:24 UTC (rev 301462) @@ -0,0 +1,90 @@ +<?php +// $Id $ +$_SERVER['BASE_PAGE'] = 'releases/5_3_3.php'; +include_once $_SERVER['DOCUMENT_ROOT'] . '/include/prepend.inc'; +site_header("PHP 5.3.3 Release Announcement"); +?> + +<h1>PHP 5.3.3 Release Announcement</h1> +<p> +The PHP development team would like to announce the immediate +availability of PHP 5.3.3. This release focuses on improving the +stability and security of the PHP 5.3.x branch with over 100 bug +fixes, some of which are security related. All users are encouraged +to upgrade to this release. +</p> + +<p> +<b>Backwards incompatible change:</b> +</p> +<ul> + <li>Methods with the same name as the last element of a namespaced class name + will no longer be treated as constructor. This change doesn't affect + non-namespaced classes. + + <?php + highlight_string('<?php +namespace Foo; +class Bar { + public function Bar() { + // treated as constructor in PHP 5.3.0-5.3.2 + // treated as regular method in PHP 5.3.3 + } +} +?>'); + ?> + There is no impact on migration from 5.2.x because namespaces were only introduced in PHP 5.3.</li> +</ul> +<p> +<b>Security Enhancements and Fixes in PHP 5.3.3:</b> +</p> +<ul> + <li>Rewrote var_export() to use smart_str rather than output buffering, prevents data disclosure if a fatal error occurs (CVE-2010-2531).</li> + <li>Fixed a possible resource destruction issues in shm_put_var().</li> + <li>Fixed a possible information leak because of interruption of XOR operator.</li> + <li>Fixed a possible memory corruption because of unexpected call-time pass by refernce and following memory clobbering through callbacks.</li> + <li>Fixed a possible memory corruption in ArrayObject::uasort().</li> + <li>Fixed a possible memory corruption in parse_str().</li> + <li>Fixed a possible memory corruption in pack().</li> + <li>Fixed a possible memory corruption in substr_replace().</li> + <li>Fixed a possible memory corruption in addcslashes().</li> + <li>Fixed a possible stack exhaustion inside fnmatch().</li> + <li>Fixed a possible dechunking filter buffer overflow.</li> + <li>Fixed a possible arbitrary memory access inside sqlite extension.</li> + <li>Fixed string format validation inside phar extension.</li> + <li>Fixed handling of session variable serialization on certain prefix characters.</li> + <li>Fixed a NULL pointer dereference when processing invalid XML-RPC requests (Fixes CVE-2010-0397, bug #51288).</li> + <li>Fixed SplObjectStorage unserialization problems (CVE-2010-2225).</li> + <li>Fixed possible buffer overflows in mysqlnd_list_fields, mysqlnd_change_user.</li> + <li>Fixed possible buffer overflows when handling error packets in mysqlnd.</li> +</ul> + +<p> +<b>Key enhancements in PHP 5.3.3 include:</b> +</p> +<ul> + <li>Upgraded bundled sqlite to version 3.6.23.1.</li> + <li>Upgraded bundled PCRE to version 8.02.</li> + <li>Added FastCGI Process Manager (FPM) SAPI.</li> + <li>Added stream filter support to mcrypt extension.</li> + <li>Added full_special_chars filter to ext/filter.</li> + <li>Fixed a possible crash because of recursive GC invocation.</li> + <li>Fixed bug #52238 (Crash when an Exception occured in iterator_to_array).</li> + <li>Fixed bug #52041 (Memory leak when writing on uninitialized variable returned from function).</li> + <li>Fixed bug #52060 (Memory leak when passing a closure to method_exists()).</li> + <li>Fixed bug #52001 (Memory allocation problems after using variable variables).</li> + <li>Fixed bug #51723 (Content-length header is limited to 32bit integer with Apache2 on Windows).</li> + <li>Fixed bug #48930 (__COMPILER_HALT_OFFSET__ incorrect in PHP &gt;= 5.3).</li> +</ul> + +<p> +For users upgrading from PHP 5.2 there is a migration guide available on +<a href="/migration53">http://php.net/migration53</a>, detailing the changes between those +releases and PHP 5.3. +</p> + +<p> + For a full list of changes in PHP 5.3.3, see the <a href="/ChangeLog-5.php#5.3.3">ChangeLog</a>. +</p> + +<?php site_footer(); ?>

« previous php.webmaster (#8567) next »