]>
granicus.if.org Git - php/log
Antony Dovgal [Mon, 26 Mar 2007 10:25:41 +0000 (10:25 +0000)]
MFH: fix #40915 (addcslashes unexpected behavior with binary input)
Marcus Boerger [Sun, 25 Mar 2007 12:53:47 +0000 (12:53 +0000)]
- MFH Need to install headers
Hannes Magnusson [Sun, 25 Mar 2007 11:47:27 +0000 (11:47 +0000)]
Typo
foobar [Sun, 25 Mar 2007 10:21:02 +0000 (10:21 +0000)]
- Check if Makefile.frag actually exists before running sed on it.
foobar [Sun, 25 Mar 2007 01:14:51 +0000 (01:14 +0000)]
- Fixed test to skip when mysqld is not running
Marcus Boerger [Sat, 24 Mar 2007 16:28:53 +0000 (16:28 +0000)]
- MFH Drop double variable declaration
Ilia Alshanetsky [Sat, 24 Mar 2007 16:25:42 +0000 (16:25 +0000)]
Fixed CRLF injection inside ftp_putcmd().
# Reported on BugTraq by loveshell[at]Bug.Center.Team
Nuno Lopes [Fri, 23 Mar 2007 20:28:40 +0000 (20:28 +0000)]
regenerate to fix gcov build. plus use re2c bitvectors
Stanislav Malyshev [Fri, 23 Mar 2007 20:22:52 +0000 (20:22 +0000)]
fix MOPB-29 - unserialize modifier S does not calculate length correctly
Stanislav Malyshev [Fri, 23 Mar 2007 20:15:22 +0000 (20:15 +0000)]
fix MOPB-29 - unserialize modifier S does not calculate length correctly
# reported by Stefan Esser
Stanislav Malyshev [Fri, 23 Mar 2007 17:16:55 +0000 (17:16 +0000)]
fix comment - guard system changed
Wez Furlong [Fri, 23 Mar 2007 14:30:00 +0000 (14:30 +0000)]
export the module guy in the external dll version of the build
Dmitry Stogov [Fri, 23 Mar 2007 12:46:16 +0000 (12:46 +0000)]
Fixed bug #40899 (memory leak when nesting list())
Dmitry Stogov [Fri, 23 Mar 2007 07:59:26 +0000 (07:59 +0000)]
Fixed bug #40883 (mysql_query() is allocating memory incorrectly). (Tony)
Ilia Alshanetsky [Thu, 22 Mar 2007 23:34:14 +0000 (23:34 +0000)]
Added -- test case
Douglas Goldstein [Thu, 22 Mar 2007 21:50:34 +0000 (21:50 +0000)]
Replaced all instances of ldap_get_values() with ldap_get_values_len(), which returns back the length of the data so on non-NULL terminated data we don't crash in a strlen(). Removed the PHP function ldap_get_values() since it's the same thing as ldap_get_values_len() now and made it alias ldap_get_values_len(). This should fix some random PHP<->LDAP crashes
Johannes Schlüter [Thu, 22 Mar 2007 21:35:41 +0000 (21:35 +0000)]
- MFH: Fix handling of not existing long CLI options
Wez Furlong [Thu, 22 Mar 2007 01:00:23 +0000 (01:00 +0000)]
Add php_pdo_sqlite_external.dll to windows build.
This allows the user to provide their own version of sqlite3.dll.
The php_pdo_sqlite.dll is still there, and will continue to be there.
It is built from the bundled sources.
[[DOC]]
(this should cc: phpdoc, if it's wrong, please let the docs folks know :-)
Marcus Boerger [Wed, 21 Mar 2007 23:20:21 +0000 (23:20 +0000)]
- MFH Fix issue with long form of command line switches
Derick Rethans [Wed, 21 Mar 2007 09:40:33 +0000 (09:40 +0000)]
- Revert this patch, as the code was incorrect.
- It was also not committed to HEAD.
Ilia Alshanetsky [Wed, 21 Mar 2007 00:25:55 +0000 (00:25 +0000)]
Fixed bug #40861 (Multiple +/- on relative units breaks strtotime()).
Marcus Boerger [Tue, 20 Mar 2007 20:28:08 +0000 (20:28 +0000)]
- MFH Fix Bug #40872 (inconsistency in offsetSet, offsetExists treatment
of string enclosed integers)
Marcus Boerger [Tue, 20 Mar 2007 20:00:27 +0000 (20:00 +0000)]
- MFH Optional dependency for SPL must be specified in header
Antony Dovgal [Tue, 20 Mar 2007 19:39:27 +0000 (19:39 +0000)]
BFN
Antony Dovgal [Tue, 20 Mar 2007 17:57:59 +0000 (17:57 +0000)]
MFH: fix shmop_open() with IPC_CREAT|IPC_EXCL flags on win32
Dmitry Stogov [Tue, 20 Mar 2007 09:52:14 +0000 (09:52 +0000)]
Added ability to encode arrays with "SOAP-ENC:Array" type instead of WSDL type. To activate the ability use "feature"=>SOAP_USE_XSI_ARRAY_TYPE option in SoapClient/SoapServer constructors.
Dmitry Stogov [Tue, 20 Mar 2007 07:51:32 +0000 (07:51 +0000)]
Fixed bug #36226 (Inconsistent handling when passing nillable arrays)
Dmitry Stogov [Tue, 20 Mar 2007 06:46:48 +0000 (06:46 +0000)]
Improved Zend Memory Manager to guarantee reasonable time for worst cases of best-fit free block searching algorithm.
Ilia Alshanetsky [Mon, 19 Mar 2007 22:56:57 +0000 (22:56 +0000)]
Fixed bug #40854 (imap_mail_compose() creates an invalid terminator for
multipart e-mails).
Dmitry Stogov [Mon, 19 Mar 2007 18:31:30 +0000 (18:31 +0000)]
Fixed bug #40833 (Crash when using unset() on an ArrayAccess object retrieved via __get())
Antony Dovgal [Mon, 19 Mar 2007 08:11:14 +0000 (08:11 +0000)]
new test
Edin Kadribasic [Mon, 19 Mar 2007 03:15:48 +0000 (03:15 +0000)]
Make DLL only once (Wez)
Rob Richards [Sun, 18 Mar 2007 21:31:57 +0000 (21:31 +0000)]
BFN
Rob Richards [Sun, 18 Mar 2007 21:31:05 +0000 (21:31 +0000)]
MFH: fix bug #40836 (Segfault in ext/dom)
add test
Wez Furlong [Sun, 18 Mar 2007 20:21:43 +0000 (20:21 +0000)]
BFN, #40848
Wez Furlong [Sun, 18 Mar 2007 20:20:23 +0000 (20:20 +0000)]
fixes #40848
Ilia Alshanetsky [Sun, 18 Mar 2007 16:36:13 +0000 (16:36 +0000)]
Fixed MOPB-26-2007 mb_parse_str() can be used to activate register_globals
# Discovered by Stefan Esser
Antony Dovgal [Sat, 17 Mar 2007 23:00:49 +0000 (23:00 +0000)]
MFH: fix #40794 (ReflectionObject::getValues() may crash when used with dynamic properties)
Antony Dovgal [Sat, 17 Mar 2007 19:16:17 +0000 (19:16 +0000)]
fix tests
Stanislav Malyshev [Fri, 16 Mar 2007 21:59:23 +0000 (21:59 +0000)]
fix spprintf usage
Stanislav Malyshev [Fri, 16 Mar 2007 21:49:56 +0000 (21:49 +0000)]
clarify
Stanislav Malyshev [Fri, 16 Mar 2007 19:58:19 +0000 (19:58 +0000)]
array_user_key_compare() fix
Stanislav Malyshev [Fri, 16 Mar 2007 19:55:21 +0000 (19:55 +0000)]
add test
Stanislav Malyshev [Fri, 16 Mar 2007 19:38:58 +0000 (19:38 +0000)]
Fix UMR in array_user_key_compare() (MOPB24 by Stefan Esser)
Antony Dovgal [Fri, 16 Mar 2007 09:31:20 +0000 (09:31 +0000)]
BFN
Sebastian Bergmann [Fri, 16 Mar 2007 06:41:24 +0000 (06:41 +0000)]
Fugbix typo.
Antony Dovgal [Thu, 15 Mar 2007 22:33:04 +0000 (22:33 +0000)]
fix #40805 (Failure executing function ibase_execute())
Antony Dovgal [Thu, 15 Mar 2007 16:44:35 +0000 (16:44 +0000)]
BFN
Antony Dovgal [Thu, 15 Mar 2007 16:44:12 +0000 (16:44 +0000)]
fix #40815 (using strings like "class::func" and static methods in set_exception_handler() might result in crash)
Antony Dovgal [Wed, 14 Mar 2007 23:47:44 +0000 (23:47 +0000)]
MFH: remove unnecessary warning in case of exception
Ilia Alshanetsky [Wed, 14 Mar 2007 19:37:07 +0000 (19:37 +0000)]
Fixed MOPB-22-2007:PHP session_regenerate_id() Double Free Vulnerability
# Discovered by Stefan Esser
Antony Dovgal [Wed, 14 Mar 2007 19:22:14 +0000 (19:22 +0000)]
MFH: fix #40750 (openssl stream wrapper ignores default_stream_timeout)
Pierre Joye [Wed, 14 Mar 2007 16:36:16 +0000 (16:36 +0000)]
- leak in extract
Pierre Joye [Wed, 14 Mar 2007 15:10:37 +0000 (15:10 +0000)]
- add ::open to the safemode check entry
Ilia Alshanetsky [Wed, 14 Mar 2007 15:02:20 +0000 (15:02 +0000)]
Fixed a possible memory leak on open_basedir validation
Pierre Joye [Wed, 14 Mar 2007 12:06:20 +0000 (12:06 +0000)]
- MFH: openbasedir and safemode check in ::open()
Antony Dovgal [Wed, 14 Mar 2007 11:58:18 +0000 (11:58 +0000)]
BFN
Antony Dovgal [Wed, 14 Mar 2007 11:58:05 +0000 (11:58 +0000)]
MFH: fix #40800 (cannot disable memory_limit with -1)
Timm Friebe [Wed, 14 Mar 2007 11:57:45 +0000 (11:57 +0000)]
- Changed message handler also to handle message #11021
- Adjusted expected output
# Seems newer Sybase versions yielf different error codes for getdate(NULL)
Timm Friebe [Wed, 14 Mar 2007 11:48:49 +0000 (11:48 +0000)]
- Fixed segmentation fault in sybase_connect()
# This was introduced by changing sprintf -> spprintf and resulted
# from passing a char* to spprintf() instead of a char**
Timm Friebe [Wed, 14 Mar 2007 11:46:06 +0000 (11:46 +0000)]
- Changed expected output
# select getdate() returns something like "Mar 14 2007 12:44PM", we
# were checking for one additional (nonexistant) whitespace after "Mar"
# which was wrong. Don`t know when and how this changed
Timm Friebe [Wed, 14 Mar 2007 11:44:24 +0000 (11:44 +0000)]
- Changed expected output
# Due to var_export() & __set_state() changes
Pierre Joye [Wed, 14 Mar 2007 11:32:25 +0000 (11:32 +0000)]
- MFH: Fixed possible relative path issues in zip_open in TS mode (old API)
Pierre Joye [Wed, 14 Mar 2007 11:08:57 +0000 (11:08 +0000)]
- rename SAFEMODE_CHECKFILE to OPENBASEDIR_CHECKPATH (can be used without
confusing in head without confusion)
- Add safemode and open basedir checks in zip:// wrapper (revert Ilia's
patch). Bug found by Stefan Esser in his MOPB-20-2007
Pierre Joye [Wed, 14 Mar 2007 11:02:29 +0000 (11:02 +0000)]
- add more cases for getComment
Martin Kraemer [Wed, 14 Mar 2007 09:58:14 +0000 (09:58 +0000)]
Typo
Ilia Alshanetsky [Wed, 14 Mar 2007 03:50:18 +0000 (03:50 +0000)]
Added missing open_basedir & safe_mode checks to zip:// and bzip://
wrappers.
Issues idendtified by MOPB-20 and MOPB-21
Stanislav Malyshev [Tue, 13 Mar 2007 00:04:38 +0000 (00:04 +0000)]
fix odbc resource handling, patch by Dave Lawson
Antony Dovgal [Mon, 12 Mar 2007 23:42:26 +0000 (23:42 +0000)]
return false instead of empty string when -length is greater than (len - offset)
Ilia Alshanetsky [Mon, 12 Mar 2007 23:21:41 +0000 (23:21 +0000)]
malloc() -> pemalloc()
Antony Dovgal [Mon, 12 Mar 2007 20:55:15 +0000 (20:55 +0000)]
MFH
Antony Dovgal [Mon, 12 Mar 2007 19:34:26 +0000 (19:34 +0000)]
synchronize iconv_substr() behavior with substr()
no MFB so far, since substr() changes are not MFBed either
Dmitry Stogov [Mon, 12 Mar 2007 16:59:52 +0000 (16:59 +0000)]
Fixed bug #40770 (Apache child exits when PHP memory limit reached)
Antony Dovgal [Mon, 12 Mar 2007 13:10:55 +0000 (13:10 +0000)]
BFN
Antony Dovgal [Mon, 12 Mar 2007 13:10:40 +0000 (13:10 +0000)]
MFH: fix #40784 (Case sensivity in constructor's fallback)
Dmitry Stogov [Mon, 12 Mar 2007 07:39:01 +0000 (07:39 +0000)]
Fixed compilation warning
Edin Kadribasic [Mon, 12 Mar 2007 03:10:08 +0000 (03:10 +0000)]
Lib upgrade news
Ilia Alshanetsky [Sun, 11 Mar 2007 18:42:19 +0000 (18:42 +0000)]
malloc() -> pemalloc()
Antony Dovgal [Sun, 11 Mar 2007 12:56:44 +0000 (12:56 +0000)]
MFH
Antony Dovgal [Sun, 11 Mar 2007 12:54:54 +0000 (12:54 +0000)]
fix tests
Ilia Alshanetsky [Sat, 10 Mar 2007 20:07:50 +0000 (20:07 +0000)]
Re-added check removed by the previous patch
Ilia Alshanetsky [Sat, 10 Mar 2007 19:20:16 +0000 (19:20 +0000)]
Added additional checks for long input arrays inside
import_request_variables().
# Missing checks identified by Stefan Esser
Pierre Joye [Sat, 10 Mar 2007 12:18:36 +0000 (12:18 +0000)]
- MFH: CVE-2007-1001, integer overflow with invalid wbmp images
Pierre Joye [Sat, 10 Mar 2007 01:13:19 +0000 (01:13 +0000)]
- #40764, line thickness not respected for horizontal and vertical lines
- add test
- NEWS entry
Stanislav Malyshev [Fri, 9 Mar 2007 18:37:03 +0000 (18:37 +0000)]
add testcase
Dmitry Stogov [Fri, 9 Mar 2007 16:46:07 +0000 (16:46 +0000)]
Return HTTP 403 in case of "access denied".
Antony Dovgal [Fri, 9 Mar 2007 10:04:59 +0000 (10:04 +0000)]
fix substr()
it's perfectly legal to do substr("str", 0,
1000000 );
Antony Dovgal [Fri, 9 Mar 2007 09:45:14 +0000 (09:45 +0000)]
fix tests
Ilia Alshanetsky [Fri, 9 Mar 2007 01:58:34 +0000 (01:58 +0000)]
Fixed bug #40754 (added substr() & substr_replace() overflow checks).
Ilia Alshanetsky [Fri, 9 Mar 2007 01:48:56 +0000 (01:48 +0000)]
Add _SESSION to checklist
Ilia Alshanetsky [Fri, 9 Mar 2007 01:42:20 +0000 (01:42 +0000)]
Fixed a possible super-global overwrite inside import_request_variables().
# Reported by Stefano Di Paola
Rasmus Lerdorf [Fri, 9 Mar 2007 01:20:34 +0000 (01:20 +0000)]
Off by ! in the url control char check for file:/// urls
Pierre Joye [Fri, 9 Mar 2007 01:18:40 +0000 (01:18 +0000)]
- #40764, line thickness not respected for horizontal and vertical lines
Stanislav Malyshev [Thu, 8 Mar 2007 22:53:37 +0000 (22:53 +0000)]
more fixes
Stanislav Malyshev [Thu, 8 Mar 2007 22:49:53 +0000 (22:49 +0000)]
fix crash/leak in bug #38710
Stanislav Malyshev [Thu, 8 Mar 2007 22:44:22 +0000 (22:44 +0000)]
add news
Nuno Lopes [Thu, 8 Mar 2007 22:04:33 +0000 (22:04 +0000)]
BFN: gd gif reading
Stanislav Malyshev [Thu, 8 Mar 2007 20:59:31 +0000 (20:59 +0000)]
fix crash on $x['x']['y'] += 1, patch by Brian Shire
Nuno Lopes [Thu, 8 Mar 2007 20:24:53 +0000 (20:24 +0000)]
fix thread unsafety in the gif reader code (merge from libgd cvs)
Stanislav Malyshev [Thu, 8 Mar 2007 00:47:04 +0000 (00:47 +0000)]
clarify checks and error messages