PHP NEWS
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
-?? ??? 2018, PHP 7.1.26
+?? ??? 2019, PHP 7.2.15
+
++- Core:
++ . Fixed bug #77369 (memcpy with negative length via crafted DNS response). (Stas)
+
- GD:
- . Fixed bug #77269 (efree() on uninitialized Heap data in imagescale leads to
++ . Fixed bug #77269 (efree() on uninitialized Heap data in imagescale leads to
+ use-after-free). (cmb)
+ . Fixed bug #77270 (imagecolormatch Out Of Bounds Write on Heap). (cmb)
-
-- IMAP:
- . Fixed bug #77020 (null pointer dereference in imap_mail). (cmb)
+ . Fixed bug #77391 (1bpp BMPs may fail to be loaded). (Romain Déoux, cmb)
- . Fixed bug #77371 (heap buffer overflow in mb regex functions
+ - Mbstring:
+ . Fixed bug #77370 (Buffer overflow on mb regex functions - fetch_token). (Stas)
- . Fixed bug #77382 (heap buffer overflow due to incorrect length in
++ . Fixed bug #77371 (heap buffer overflow in mb regex functions
+ - compile_string_node). (Stas)
+ . Fixed bug #77381 (heap buffer overflow in multibyte match_at). (Stas)
-06 Dec 2018, PHP 7.1.25
++ . Fixed bug #77382 (heap buffer overflow due to incorrect length in
+ expand_case_fold_string). (Stas)
+ . Fixed bug #77385 (buffer overflow in fetch_token). (Stas)
+ . Fixed bug #77394 (Buffer overflow in multibyte case folding - unicode). (Stas)
+
+- MySQLnd:
+ . Fixed bug #75684 (In mysqlnd_ext_plugin.h the plugin methods family has
+ no external visibility). (Anatol)
+
+- PDO:
+ . Fixed bug #77273 (array_walk_recursive corrupts value types leading to PDO
+ failure). (Nikita)
+
+ - Phar:
+ . Fixed bug #77247 (heap buffer overflow in phar_detect_phar_fname_ext). (Stas)
+
+- Sockets:
+ . Fixed bug #76839 (socket_recvfrom may return an invalid 'from' address
+ on MacOS). (Michael Meyer)
+
+- Standard:
+ . Fixed bug #77395 (segfault about array_multisort). (Laruence)
+
+ - Xmlrpc:
+ . Fixed bug #77242 (heap out of bounds read in xmlrpc_decode()). (cmb)
+ . Fixed bug #77380 (Global out of bounds read in xmlrpc base64 code). (Stas)
+
+03 Jan 2019, PHP 7.2.14
- Core:
. Fixed bug #71041 (zend_signal_startup() needs ZEND_API).