PHP 5.2.2 and PHP 4.4.7 Released

Original post provide by PHP: Hypertext Preprocessor

The PHP development team would like to announce the immediate availability of PHP 5.2.2 and availability of PHP 4.4.7. These releases are major stability and security enhancements of the 5.x and 4.4.x branches, and all users are strongly encouraged to upgrade to it as soon as possible. Further details about the PHP 5.2.2 release can be found in the release announcement for 5.2.2, the full list of changes is available in the ChangeLog for PHP 5. Details about the PHP 4.4.7 release can be found in the release announcement for 4.4.7, the full list of changes is available in the ChangeLog for PHP 4. Security Enhancements and Fixes in PHP 5.2.2 and PHP 4.4.7:Fixed CVE-2007-1001, GD wbmp used with invalid image size (by Ivan Fratric)Fixed asciiz byte truncation inside mail() (MOPB-33 by Stefan Esser)Fixed a bug in mb_parse_str() that can be used to activate register_globals (MOPB-26 by Stefan Esser)Fixed unallocated memory access/double free in in array_user_key_compare() (MOPB-24 by Stefan Esser)Fixed a double free inside session_regenerate_id() (MOPB-22 by Stefan Esser)Added missing open_basedir & safe_mode checks to zip:// and bzip:// wrappers. (MOPB-21 by Stefan Esser).Fixed CRLF injection inside ftp_putcmd(). (by loveshell[at]Bug.Center.Team)Fixed a remotely trigger-able buffer overflow inside bundled libxmlrpc library. (by Stanislav Malyshev)Security Enhancements and Fixes in PHP 5.2.2 only:Fixed a header injection via Subject and To parameters to the mail() function (MOPB-34 by Stefan Esser)Fixed wrong length calculation in unserialize S type (MOPB-29 by Stefan Esser)Fixed substr_compare and substr_count information leak (MOPB-14 by Stefan Esser) (Stas, Ilia)Fixed a remotely trigger-able buffer overflow inside make_http_soap_request(). (by Ilia Alshanetsky)Fixed a buffer overflow inside user_filter_factory_create(). (by Ilia Alshanetsky)Fixed a possible super-global overwrite inside import_request_variables(). (by Stefano Di Paola, Stefan Esser)Limit nesting level of input variables with max_input_nesting_level as fix for (MOPB-03 by Stefan Esser)Security Enhancements and Fixes in PHP 4.4.7 only:XSS in phpinfo() (MOPB-8 by Stefan Esser) While majority of the issues outlined above are local, in some circumstances given specific code paths they can be triggered externally. Therefor, we strongly recommend that if you use code utilizing the functions and extensions identified as having had vulnerabilities in them, you consider upgrading your PHP. For users upgrading to PHP 5.2 from PHP 5.0 and PHP 5.1, an upgrade guide is available here, detailing the changes between those releases and PHP 5.2.2. Update: May 4th; The PHP 4.4.7 Windows build was updated due to the faulty Apache2 module shipped with the originalUpdate: May 23th; By accident a couple of fixes where listed as fixed in both PHP 5.2.2 and 4.4.7 but where however only fixed in PHP 5.2.2. The PHP 4 ChangeLog was not affected.

Previous Articles:
Browserfarm
Browserfarm zum Testen von Web Seiten mit folgenden Browsern: Internet Explorer 7.0 Internet Explorer 6.0 Internet Explorer 5.5 Internet Explorer 5.0 Firefox 3.0a (Nightly Build) Firefox 2.0 Firefox 1.5 (JRE 1.5) Firefox 1.5 (JRE 1.4) Firefox 1.0 Konqueror 3.5 Opera 9.0 elinks 0.10
Easy Reflections V2
Easy Reflection is a PHP script that will take any given image (jpeg, png) and create a 'reflection' of it, ala Apple iTunes style. You can control the height, the intensity, the background colour and more. Monte has deployed this script all over a new site he built (http://www.motortopia.com) and I too integrated it into a private gallery system, so it can cut the mustard if you have a need for it.
Email Marketing Strategy: Shortcuts To Success
Having trouble keeping your email marketing efforts on target? Let Jeanne help you create a comprehensive email marketing strategy from scratch! This hands-on primer shows you how to build a strategy that lets you contact the right people at the right time -- with the right offer.
A Big Pfutt To Windows Vista
I'm about to buy a notebook for my mum, and all the one's I'm looking at have Vista preinstalled. Pfutt. Beyond the obvious playback-quality implications of deliberately degraded output, this measure can have serious repercussions in applications where high-quality reproduction of content is vital.
The New Documentation Build System Is Ready For Testing
The PHP documentation team is pleased to announce the initial release of the new build system that generates the PHP Manual. Written in PHP, PhD ([PH]P based [D]ocBook renderer) builds are now available for viewing at docs.php.net. Everyone is encouraged to test and use this system so that bugs will be found and squashed.
More Articles:
Easy Reflections V3
This version brings about some significant advances, including full support for PNG alpha transparency in the source image, alpha transparency in the output image allowing for overlaying the mirrored images on-top of complex backgrounds or gradients, and colour tinting / saturation support.
Flip A Web Site Fixer-upper
Want to buy and sell web sites for profit? In this practical guide, experienced site flipper Peter steps through the process, providing tips to keep you from the common pitfalls, and showing how to add value that translates to real profits when you sell.
SSH Tunnel
Als letzter Parameter wird der Name des Useraccounts auf meinem Rechner zu Hause, jedoch der Hostname "localhost" angegeben (da ich mich wie weiter oben ja schon beschrieben, per 'ssh harald@localhost' direkt von der Workstation in der Arbeit auf meinem Rechner zu Hause einloggen kann.
Screen Capture Software
Easily record, edit, and share professional-quality videos. Create compelling lectures, screencasts, and presentation videos by recording activity on your PC screen. Record your screen, PowerPoint, multiple audio tracks, and webcam video to create compelling videos without ever leaving your desk.
The Principles Of Beautiful Web Design
and break when you look at your own? You don't need to go to art school to create those sweet designs, as Jason explains. Read his hands-on tour of the underlying concepts of web page layout and composition today, and you'll be designing professional-level, great-looking web pages tomorrow!

Leave a Reply