./lang/php72, PHP Hypertext Preprocessor version 7.2

[ CVSweb ] [ Homepage ] [ RSS ] [ Required by ] [ Add to tracker ]


Branch: pkgsrc-2018Q4, Version: 7.2.14, Package name: php-7.2.14, Maintainer: pkgsrc-users

PHP is a widely-used open source general-purpose scripting language
that is especially suited for web development and can be embedded
into HTML. It is modular, and object-oriented. Much of its syntax
is borrowed from C, Java and Perl with a couple of unique PHP-specific
features thrown in. The language is designed to allow web developers
to write dynamically generated pages quickly.

This package provides PHP version 7.2.x.

PHP 7.2.x builds upon 7.1.x, adding new features:

* Argument type declarations
* Object return type declarations
* Parameter Type Widening
* Trailing commas in list syntax
* HashContext as Object
* Argon2 in password hash
* Libsodium as part of PHP Core
* Deprecated: __autoload, $php_errormsg, create_function(),
mbstring.func_overload, parse_str() without second argument,
gmp_random(), each(), assert(), $errcontext
* uniqid() patch to avoid usleep() integrated, 10000x improvement on NetBSD,
about 10x on Linux


Required to run:
[devel/readline] [devel/pcre] [textproc/libxml2]

Required to build:
[pkgtools/cwrappers]

Package options: inet6, readline, ssl

Master sites: (Expand)

SHA1: 97d0bfc6f75d82e8ef9425189ca5c544866f927e
RMD160: 886704673d55837144946731f6137549d4f963ac
Filesize: 14686.599 KB

Version history: (Expand)


CVS history: (Expand)


   2019-01-19 22:44:08 by Benny Siegert | Files touched by this commit (2) | Package updated
Log message:
Pullup ticket #5897 - requested by taca
lang/php72: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.243
- lang/php72/Makefile                                           1.16
- lang/php72/distinfo                                           1.35

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Sat Jan 12 14:59:03 UTC 2019

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php72: Makefile distinfo

   Log message:
   lang/php72: update to 7.2.14

   10 Jan 2019, PHP 7.2.14

   - Core:
     . Fixed bug #77369 (memcpy with negative length via crafted DNS response). \ 
(Stas)
     . Fixed bug #71041 (zend_signal_startup() needs ZEND_API).
       (Valentin V. Bartenev)
     . Fixed bug #76046 (PHP generates "FE_FREE" opcode on the wrong line).
       (Nikita)

   - COM:
     . Fixed bug #77177 (Serializing or unserializing COM objects crashes). (cmb)

   - Date:
     . Fixed bug #77097 (DateTime::diff gives wrong diff when the actual diff is
       less than 1 second). (Derick)

   - Exif:
     . Fixed bug #77184 (Unsigned rational numbers are written out as signed
       rationals). (Colin Basnett)

   - GD:
     . Fixed bug #77269 (efree() on uninitialized Heap data in imagescale leads to
       use-after-free). (cmb)
     . Fixed bug #77270 (imagecolormatch Out Of Bounds Write on Heap). (cmb)
     . Fixed bug #77195 (Incorrect error handling of imagecreatefromjpeg()). (cmb)
     . Fixed bug #77198 (auto cropping has insufficient precision). (cmb)
     . Fixed bug #77200 (imagecropauto(…, GD_CROP_SIDES) crops left but \ 
not right).
       (cmb)

   - IMAP:
     . Fixed bug #77020 (null pointer dereference in imap_mail). (cmb)

   - Mbstring:
     . Fixed bug #77370 (Buffer overflow on mb regex functions - fetch_token). (Stas)
     . Fixed bug #77371 (heap buffer overflow in mb regex functions
       - compile_string_node). (Stas)
     . Fixed bug #77381 (heap buffer overflow in multibyte match_at). (Stas)
     . Fixed bug #77382 (heap buffer overflow due to incorrect length in
       expand_case_fold_string). (Stas)
     . Fixed bug #77385 (buffer overflow in fetch_token). (Stas)
     . Fixed bug #77394 (Buffer overflow in multibyte case folding - unicode). (Stas)
     . Fixed bug #77418 (Heap overflow in utf32be_mbc_to_code). (Stas)

   - OCI8:
     . Fixed bug #76804 (oci_pconnect with OCI_CRED_EXT not working). (KoenigsKind)
     . Added oci_set_call_timeout() for call timeouts.
     . Added oci_set_db_operation() for the DBOP end-to-end-tracing attribute.

   - Opcache:
     . Fixed bug #77215 (CFG assertion failure on multiple finalizing switch
       frees in one block). (Nikita)

   - PDO:
     . Handle invalid index passed to PDOStatement::fetchColumn() as error. (Sergei
       Morozov)

   - Phar:
     . Fixed bug #77247 (heap buffer overflow in phar_detect_phar_fname_ext). (Stas)

   - Sockets:
     . Fixed bug #77136 (Unsupported IPV6_RECVPKTINFO constants on macOS).
       (Mizunashi Mana)

   - SQLite3:
     . Fixed bug #77051 (Issue with re-binding on SQLite3). (BohwaZ)

   - Xmlrpc:
     . Fixed bug #77242 (heap out of bounds read in xmlrpc_decode()). (cmb)
     . Fixed bug #77380 (Global out of bounds read in xmlrpc base64 code). (Stas)