History log of /PHP-7.1/NEWS (Results 1 – 25 of 10129)
Revision (<<< Hide revision tags) (Show revision tags >>>) Date Author Comments
Revision tags: php-7.3.13RC1, php-7.2.26RC1, php-7.4.0, php-7.2.25, php-7.3.12, php-7.4.0RC6, php-7.3.12RC1, php-7.2.25RC1, php-7.4.0RC5
# 52f04987 22-Oct-2019 Joe Watkins

bump version


Revision tags: php-7.1.33
# 326cd05d 22-Oct-2019 Joe Watkins

set versions for release


Revision tags: php-7.2.24, php-7.3.11, php-7.4.0RC4
# ab061f95 12-Oct-2019 Jakub Zelenka

Fix bug #78599 (env_path_info underflow can lead to RCE) (CVE-2019-11043)


Revision tags: php-7.3.11RC1, php-7.2.24RC1, php-7.4.0RC3, php-7.2.23, php-7.3.10, php-7.4.0RC2, php-7.2.23RC1, php-7.3.10RC1, php-7.4.0RC1
# fadd7f0f 28-Aug-2019 Joe Watkins

bump versions after release


Revision tags: php-7.1.32
# 481520d3 28-Aug-2019 Joe Watkins

set versions for release


Revision tags: php-7.2.22, php-7.3.9, php-7.4.0beta4, php-7.2.22RC1, php-7.3.9RC1, php-7.4.0beta2, php-7.1.31
# 1c01a157 31-Jul-2019 Joe Watkins

set version for release


Revision tags: php-7.2.21, php-7.3.8
# cd1101e8 29-Jul-2019 Christoph M. Becker

Fix #77919: Potential UAF in Phar RSHUTDOWN

We have to properly clean up in case phar_flush() is failing.

We also make the expectation of the respective test case less liberal
t

Fix #77919: Potential UAF in Phar RSHUTDOWN

We have to properly clean up in case phar_flush() is failing.

We also make the expectation of the respective test case less liberal
to avoid missing such bugs in the future.

show more ...


# 42e8b85d 29-Jul-2019 Stanislav Malyshev

Update NEWS


Revision tags: php-7.4.0beta1, php-7.2.21RC1, php-7.3.8RC1, php-7.4.0alpha3, php-7.3.7, php-7.2.20, php-7.4.0alpha2
# e944ae6b 21-Jun-2019 Christoph M. Becker

Upgrade to SQLite 3.28.0

Over the years, multiple security vulnerabilities[1] have been found
and fixed in SQLite3, so it makes sense to update our bundled libsqlite
to the latest av

Upgrade to SQLite 3.28.0

Over the years, multiple security vulnerabilities[1] have been found
and fixed in SQLite3, so it makes sense to update our bundled libsqlite
to the latest available version.

[1] <https://www.cvedetails.com/vulnerability-list/vendor_id-9237/Sqlite.html>

show more ...


Revision tags: php-7.3.7RC3, php-7.3.7RC2, php-7.2.20RC2, php-7.4.0alpha1, php-7.3.7RC1, php-7.2.20RC1, php-7.2.19, php-7.3.6
# 5533f249 28-May-2019 Joe Watkins

bump version after release


Revision tags: php-7.1.30
# c34895e8 28-May-2019 Stanislav Malyshev

Fix bug #77967 - Bypassing open_basedir restrictions via file uris


# 73ff4193 28-May-2019 Stanislav Malyshev

Fix bug #77988 - heap-buffer-overflow on php_jpg_get16


# 16e037bd 27-May-2019 Stanislav Malyshev

Update NEWS


Revision tags: php-7.2.19RC1, php-7.3.6RC1, php-7.1.29, php-7.2.18, php-7.3.5
# f80ad18a 30-Apr-2019 Stanislav Malyshev

Fix bug #77950 - Heap-buffer-overflow in _estrndup via exif_process_IFD_TAG

I do not completely understand what is going on there, but I am pretty
sure dir_entry <= offset_base if not a

Fix bug #77950 - Heap-buffer-overflow in _estrndup via exif_process_IFD_TAG

I do not completely understand what is going on there, but I am pretty
sure dir_entry <= offset_base if not a normal situation, so we better not
to rely on such dir_entry.

show more ...


Revision tags: php-7.2.18RC1, php-7.3.5RC1, php-7.2.17
# 731eeb8d 02-Apr-2019 Joe Watkins

bump versions after release


Revision tags: php-7.3.4, php-7.1.28
# 887a7b57 02-Apr-2019 Stanislav Malyshev

Fixed bug #77831 - Heap-buffer-overflow in exif_iif_add_value in EXIF


# c684d32f 01-Apr-2019 Stanislav Malyshev

Update NEWS


Revision tags: php-7.3.4RC1, php-7.2.17RC1, php-7.1.27, php-7.3.3, php-7.2.16, php-7.3.3RC1, php-7.2.16RC1, php-7.2.15, php-7.3.2, php-7.2.15RC1, php-7.3.2RC1, php-5.6.40, php-7.1.26, php-7.3.1, php-7.2.14, php-7.2.14RC1, php-7.3.1RC1
# 58c25bf6 16-Dec-2018 bohwaz

SQLite3: add DEFENSIVE config for SQLite >= 3.26.0 as a mitigation strategy against potential security flaws


# b6308f5b 05-Mar-2019 Joe Watkins

fix news


# 58c5df3d 05-Mar-2019 Joe Watkins

bump versions after release


# e0f5d62b 04-Mar-2019 Stanislav Malyshev

Fix bug #77586 - phar_tar_writeheaders_int() buffer overflow


# 759e841b 04-Mar-2019 Stanislav Malyshev

Update NEWS


# fabade15 08-Jan-2019 Sara Golemon

Bump for 7.1.27


# 9d6c59ee 07-Jan-2019 Stanislav Malyshev

Fix bug #77418 - Heap overflow in utf32be_mbc_to_code


# 08bb0ce4 06-Jan-2019 Stanislav Malyshev

Add NEWS


12345678910>>...406