./lang/php56, PHP Hypertext Preprocessor version 5.6

[ CVSweb ] [ Homepage ] [ RSS ] [ Required by ] [ Add to tracker ]


Branch: pkgsrc-2016Q2, Version: 5.6.26, Package name: php-5.6.26, Maintainer: pkgsrc-users

PHP is an HTML-embedded scripting language. It is modular, with
some object-oriented features. Much of its syntax is borrowed from
C, Java and Perl with a couple of unique PHP-specific features
thrown in. The language is designed to allow web developers to
write dynamically generated pages quickly.

This package provides PHP version 5.6.x.


Required to run:
[textproc/libxml2]


Package options: inet6, ssl

Master sites: (Expand)

SHA1: d0e05dbc4d1be0e316cadee64f5bda83a16932a9
RMD160: eedd93ab6808d86055a7e5f41ca3b92ea7feee63
Filesize: 14577.646 KB

Version history: (Expand)


CVS history: (Expand)


   2016-09-24 19:21:18 by Benny Siegert | Files touched by this commit (1)
Log message:
Pullup ticket #5105 - requested by taca
lang/php56: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.156
- lang/php56/distinfo                                           1.34

---
   Module Name:    pkgsrc
   Committed By:   taca
   Date:           Fri Sep 16 16:09:24 UTC 2016

   Modified Files:
           pkgsrc/lang/php: phpversion.mk
           pkgsrc/lang/php56: distinfo

   Log message:
   Update php56 to 5.6.26 (PHP 5.6.26).

   15 Sep 2016, PHP 5.6.26

   - Core:
     . Fixed bug #72907 (null pointer deref, segfault in gc_remove_zval_from_buffer
       (zend_gc.c:260)). (Laruence)

   - Dba:
     . Fixed bug #71514 (Bad dba_replace condition because of wrong API usage).
       (cmb)
     . Fixed bug #70825 (Cannot fetch multiple values with group in ini file).
       (cmb)

   - EXIF:
     . Fixed bug #72926 (Uninitialized Thumbail Data Leads To Memory Leakage in
       exif_process_IFD_in_TIFF). (Stas)

   - FTP:
     . Fixed bug #70195 (Cannot upload file using ftp_put to FTPES with
       require_ssl_reuse). (Benedict Singer)

   - GD:
     . Fixed bug #66005 (imagecopy does not support 1bit transparency on truecolor
       images). (cmb)
     . Fixed bug #72913 (imagecopy() loses single-color transparency on palette
       images). (cmb)
     . Fixed bug #68716 (possible resource leaks in _php_image_convert()). (cmb)

   - Intl:
     . Fixed bug #73007 (add locale length check). (Stas)

   - JSON:
     . Fixed bug #72787 (json_decode reads out of bounds). (Jakub Zelenka)

   - mbstring:
     . Fixed bug #66797 (mb_substr only takes 32-bit signed integer). (cmb)
     . Fixed bug #72910 (Out of bounds heap read in mbc_to_code() / triggered by
       mb_ereg_match()). (Stas)

   - MSSQL:
     . Fixed bug #72039 (Use of uninitialised value on mssql_guid_string). (Kalle)

   - Mysqlnd:
     . Fixed bug #72293 (Heap overflow in mysqlnd related to BIT fields). (Stas)

   - Phar:
     . Fixed bug #72928 (Out of bound when verify signature of zip phar in
       phar_parse_zipfile). (Stas)
     . Fixed bug #73035 (Out of bound when verify signature of tar phar in
       phar_parse_tarfile). (Stas)

   - PDO:
     . Fixed bug #60665 (call to empty() on NULL result using PDO::FETCH_LAZY
       returns false). (cmb)

   - PDO_pgsql:
     . Implemented FR #72633 (Postgres PDO lastInsertId() should work without
       specifying a sequence). (Pablo Santiago Sa'nchez, Matteo)
     . Fixed bug #72759 (Regression in pgo_pgsql). (Anatol)

   - SPL:
     . Fixed bug #73029 (Missing type check when unserializing SplArray). (Stas)

   - Standard:
     . Fixed bug #72823 (strtr out-of-bound access). (cmb)
     . Fixed bug #72278 (getimagesize returning FALSE on valid jpg). (cmb)
     . Fixed bug #65550 (get_browser() incorrectly parses entries with \ 
"+" sign).
       (cmb)
     . Fixed bug #71882 (Negative ftruncate() on php://memory exhausts memory).
       (cmb)
     . Fixed bug #73011 (integer overflow in fgets cause heap corruption). (Stas)
     . Fixed bug #73017 (memory corruption in wordwrap function). (Stas)
     . Fixed bug #73045 (integer overflow in fgetcsv caused heap corruption). (Stas)
     . Fixed bug #73052 (Memory Corruption in During Deserialized-object Destruction)
       (Stas)

   - Streams:
     . Fixed bug #72853 (stream_set_blocking doesn't work). (Laruence)

   - Wddx:
     . Fixed bug #72860 (wddx_deserialize use-after-free). (Stas)
     . Fixed bug #73065 (Out-Of-Bounds Read in php_wddx_push_element). (Stas)

   - XML:
     . Fixed bug #72085 (SEGV on unknown address zif_xml_parse). (cmb)
     . Fixed bug #72927 (integer overflow in xml_utf8_encode). (Stas)

   - ZIP:
     . Fixed bug #68302 (impossible to compile php with zip support). (cmb)
   2016-09-07 20:23:59 by Benny Siegert | Files touched by this commit (1)
Log message:
Pullup ticket #5094 - requested by taca
lang/php56: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.149
- lang/php56/distinfo                                           1.33

---
   Module Name:    pkgsrc
   Committed By:   taca
   Date:           Fri Aug 19 03:29:00 UTC 2016

   Modified Files:
           pkgsrc/lang/php: phpversion.mk
           pkgsrc/lang/php56: distinfo

   Log message:
   Update php56 to 5.6.25 (PHP 5.6.25).

   18 Aug 2016, PHP 5.6.25

   - Bz2:
     . Fixed bug #72837 (integer overflow in bzdecompress caused heap
       corruption). (Stas)

   - Core:
     . Fixed bug #70436 (Use After Free Vulnerability in unserialize()).
       (Taoguang Chen)
     . Fixed bug #72024 (microtime() leaks memory). (maroszek at gmx dot net)
     . Fixed bug #72581 (previous property undefined in Exception after
       deserialization). (Laruence)
     . Implemented FR #72614 (Support "nmake test" on building \ 
extensions by
       phpize). (Yuji Uchiyama)
     . Fixed bug #72641 (phpize (on Windows) ignores PHP_PREFIX).
       (Yuji Uchiyama)
     . Fixed bug #72663 (Create an Unexpected Object and Don't Invoke
       __wakeup() in Deserialization). (Stas)
     . Fixed bug #72681 (PHP Session Data Injection Vulnerability). (Stas)

   - Calendar:
     . Fixed bug #67976 (cal_days_month() fails for final month of the French
       calendar). (cmb)
     . Fixed bug #71894 (AddressSanitizer: global-buffer-overflow in
       zif_cal_from_jd). (cmb)

   - Curl:
     . Fixed bug #71144 (Segmentation fault when using cURL with ZTS).
       (maroszek at gmx dot net)
     . Fixed bug #71929 (Certification information (CERTINFO) data parsing error).
       (Pierrick)
     . Fixed bug #72807 (integer overflow in curl_escape caused heap
       corruption). (Stas)

   - DOM:
     . Fixed bug #66502 (DOM document dangling reference). (Sean Heelan, cmb)

   - Ereg:
     . Fixed bug #72838 (Integer overflow lead to heap corruption in
       sql_regcase). (Stas)

   - EXIF:
     . Fixed bug #72627 (Memory Leakage In exif_process_IFD_in_TIFF). (Stas)
     . Fixed bug #72735 (Samsung picture thumb not read (zero size)). (Kalle, Remi)

   - Filter:
     . Fixed bug #71745 (FILTER_FLAG_NO_RES_RANGE does not cover whole 127.0.0.0/8
       range). (bugs dot php dot net at majkl578 dot cz)

   - FPM:
     . Fixed bug #72575 (using --allow-to-run-as-root should ignore missing user).
       (gooh)

   - GD:
     . Fixed bug #43828 (broken transparency of imagearc for truecolor in
       blendingmode). (cmb)
     . Fixed bug #66555 (Always false condition in ext/gd/libgd/gdkanji.c). (cmb)
     . Fixed bug #68712 (suspicious if-else statements). (cmb)
     . Fixed bug #70315 (500 Server Error but page is fully rendered). (cmb)
     . Fixed bug #72596 (imagetypes function won't advertise WEBP support). (cmb)
     . Fixed bug #72604 (imagearc() ignores thickness for full arcs). (cmb)
     . Fixed bug #72697 (select_colors write out-of-bounds). (Stas)
     . Fixed bug #72709 (imagesetstyle() causes OOB read for empty $styles). (cmb)
     . Fixed bug #72730 (imagegammacorrect allows arbitrary write access). (Stas)

   - Intl:
     . Partially fixed #72506 (idn_to_ascii for UTS #46 incorrect for long domain
       names). (cmb)

   - mbstring:
     . Fixed bug #72691 (mb_ereg_search raises a warning if a match zero-width).
       (cmb)
     . Fixed bug #72693 (mb_ereg_search increments search position when a match
       zero-width). (cmb)
     . Fixed bug #72694 (mb_ereg_search_setpos does not accept a string's last
       position). (cmb)
     . Fixed bug #72710 (`mb_ereg` causes buffer overflow on regexp compile error).
       (ju1ius)

   - PCRE:
     . Fixed bug #72688 (preg_match missing group names in matches). (cmb)

   - PDO_pgsql:
     . Fixed bug #70313 (PDO statement fails to throw exception). (Matteo)

   - Reflection:
     . Fixed bug #72222 (ReflectionClass::export doesn't handle array constants).
       (Nikita Nefedov)

   - SNMP:
     . Fixed bug #72708 (php_snmp_parse_oid integer overflow in memory
       allocation). (djodjo at gmail dot com)

   - Standard:
     . Fixed bug #72330 (CSV fields incorrectly split if escape char followed by
       UTF chars). (cmb)
     . Fixed bug #72836 (integer overflow in base64_decode). (Stas)
     . Fixed bug #72848 (integer overflow in quoted_printable_encode). (Stas)
     . Fixed bug #72849 (integer overflow in urlencode). (Stas)
     . Fixed bug #72850 (integer overflow in php_uuencode). (Stas)
     . Fixed bug #72716 (initialize buffer before read). (Stas)

   - Streams:
     . Fixed bug #41021 (Problems with the ftps wrapper). (vhuk)
     . Fixed bug #54431 (opendir() does not work with ftps:// wrapper). (vhuk)
     . Fixed bug #72667 (opendir() with ftp:// attempts to open data stream for
       non-existent directories). (vhuk)
     . Fixed bug #72764 (ftps:// opendir wrapper data channel encryption fails
       with IIS FTP 7.5, 8.5). (vhuk)
     . Fixed bug #72771 (ftps:// wrapper is vulnerable to protocol downgrade
       attack). (Stas)

   - SPL:
     . Fixed bug #72122 (IteratorIterator breaks '@' error suppression). (kinglozzer)
     . Fixed bug #72646 (SplFileObject::getCsvControl does not return the escape
       character). (cmb)
     . Fixed bug #72684 (AppendIterator segfault with closed generator). (Pierrick)

   - SQLite3:
     . Implemented FR #72653 (SQLite should allow opening with empty filename).
       (cmb)

   - Wddx:
     . Fixed bug #72142 (WDDX Packet Injection Vulnerability in
       wddx_serialize_value()). (Taoguang Chen)
     . Fixed bug #72749 (wddx_deserialize allows illegal memory access) (Stas)
     . Fixed bug #72750 (wddx_deserialize null dereference). (Stas)
     . Fixed bug #72790 (wddx_deserialize null dereference with invalid xml).
       (Stas)
     . Fixed bug #72799 (wddx_deserialize null dereference in
       php_wddx_pop_element). (Stas)
   2016-07-28 16:58:39 by S.P.Zeidler | Files touched by this commit (1) | Package updated
Log message:
Pullup ticket #5069 - requested by taca
lang/php56: security update
lang/php: subsequent adjustment

Revisions pulled up:
- lang/php/phpversion.mk                                        1.143
- lang/php56/distinfo                                           1.29

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Sun Jul 24 02:18:02 UTC 2016

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php56: distinfo

   Log message:
   Update php56 to 5.6.24 (PHP 5.6.24).

   21 Jul 2016, PHP 5.6.24

   - Core:
     . Fixed bug #71936 (Segmentation fault destroying HTTP_RAW_POST_DATA).
       (mike dot laspina at gmail dot com, Remi)
     . Fixed bug #72496 (Cannot declare public method with signature incompatible
       with parent private method). (Pedro Magalhães)
     . Fixed bug #72138 (Integer Overflow in Length of String-typed ZVAL). (Stas)
     . Fixed bug #72513 (Stack-based buffer overflow vulnerability in
       virtual_file_ex). (loianhtuan at gmail dot com)
     . Fixed bug #72562 (Use After Free in unserialize() with Unexpected Session
       Deserialization). (taoguangchen at icloud dot com)
     . Fixed bug #72573 (HTTP_PROXY is improperly trusted by some PHP libraries and
       applications). (CVE-2016-5385) (Stas)

   - bz2:
     . Fixed bug #72447 (Type Confusion in php_bz2_filter_create()). (gogil at
       stealien dot com).
     . Fixed bug #72613 (Inadequate error handling in bzread()). (Stas)

   - EXIF:
     . Fixed bug #50845 (exif_read_data() returns corrupted exif headers).
       (Bartosz Dziewoński)
   - EXIF:
     . Fixed bug #72603 (Out of bound read in exif_process_IFD_in_MAKERNOTE).
       (Stas)
     . Fixed bug #72618 (NULL Pointer Dereference in exif_process_user_comment).
       (Stas)

   - GD:
     . Fixed bug #43475 (Thick styled lines have scrambled patterns). (cmb)
     . Fixed bug #53640 (XBM images require width to be multiple of 8). (cmb)
     . Fixed bug #64641 (imagefilledpolygon doesn't draw horizontal line). (cmb)
     . Fixed bug #72512 (gdImageTrueColorToPaletteBody allows arbitrary write/read
       access). (Pierre)
     . Fixed bug #72519 (imagegif/output out-of-bounds access). (Pierre)
     . Fixed bug #72558 (Integer overflow error within _gdContributionsAlloc()).
       (CVE-2016-6207) (Pierre)

   - Intl:
     . Fixed bug #72533 (locale_accept_from_http out-of-bounds access). (Stas)

   - ODBC:
     . Fixed bug #69975 (PHP segfaults when accessing nvarchar(max) defined columns)

   - OpenSSL:
     . Fixed bug #71915 (openssl_random_pseudo_bytes is not fork-safe).
       (Jakub Zelenka)
     . Fixed bug #72336 (openssl_pkey_new does not fail for invalid DSA params).
       (Jakub Zelenka)

   - SNMP:
     . Fixed bug #72479 (Use After Free Vulnerability in SNMP with GC and
       unserialize()). (taoguangchen at icloud dot com)

   - SPL:
     . Fixed bug #55701 (GlobIterator throws LogicException). (Valentin VĂLCIU)

   - SQLite3:
     . Fixed bug #70628 (Clearing bindings on an SQLite3 statement doesn't work).
       (cmb)

   - Streams:
     . Fixed bug #72439 (Stream socket with remote address leads to a segmentation
       fault). (Laruence)

   - Xmlrpc:
     . Fixed bug #72606 (heap-buffer-overflow (write) simplestring_addn \ 
simplestring.c).
       (Stas)

   - Zip:
     . Fixed bug #72520 (Stack-based buffer overflow vulnerability in
       php_stream_zip_opener). (loianhtuan at gmail dot com)

   To generate a diff of this commit:
   cvs rdiff -u -r1.142 -r1.143 pkgsrc/lang/php/phpversion.mk
   cvs rdiff -u -r1.28 -r1.29 pkgsrc/lang/php56/distinfo