Articles
Tutorials
Resources
RSS Feeds
Book Shop
Programmer Software
Webmaster Corner
Web Hosting Articles
Search







Windows Server Support
Server support offered on all Windows based servers from NT4 through to Windows 2003 and XP. The Century server support package can be tailored to meet your needs.

discount ink
Buy directly from the factory with us to get discount ink. After your first order with us you can get 10% off all your future orders!!!


The Complete C++ Training Course, Fourth Edition
The Complete C++ Training Course, Fourth Edition
Buy Now


Mastering Borland Delphi
Mastering Borland Delphi
Buy Now


Books : XML in a Nutshell, 2nd Edition
XML in a Nutshell
Buy Now


MySQL (3rd Edition) (Developer
MySQL (3rd Edition)
Buy Now


Beginning PHP 5 and MySQL E-Commerce: From Novice to Professional
Beginning PHP 5 and MySQL E-Commerce: From Novice to Professional
Buy Now


"Building Websites with VB.NET and DotNetNuke 3.0
"Building Websites with VB.NET and DotNetNuke 3.0
Buy Now


The Zen of CSS Design : Visual Enlightenment for the Web (Voices That Matter)
The Zen of CSS Design
Buy Now


 


  HOME >> PHP >> Programming Tutorial

 

PHP 5.2.2 and PHP 4.4.7 Released
Ranking:Your Ranking:
The PHP development team would like to announce the immediate availability of PHP 5.2.2 and availability of PHP 4.4.7. These releases are major stability and security enhancements of the 5.x and 4.4.x branches, and all users are strongly encouraged to upgrade to it as soon as possible. Further details about the PHP 5.2.2 release can be found in the release announcement for 5.2.2, the full list of changes is available in the ChangeLog for PHP 5. Details about the PHP 4.4.7 release can be found in the release announcement for 4.4.7, the full list of changes is available in the ChangeLog for PHP 4. Security Enhancements and Fixes in PHP 5.2.2 and PHP 4.4.7:Fixed CVE-2007-1001, GD wbmp used with invalid image size (by Ivan Fratric)Fixed asciiz byte truncation inside mail() (MOPB-33 by Stefan Esser)Fixed a bug in mb_parse_str() that can be used to activate register_globals (MOPB-26 by Stefan Esser)Fixed unallocated memory access/double free in in array_user_key_compare() (MOPB-24 by Stefan Esser)Fixed a double free inside session_regenerate_id() (MOPB-22 by Stefan Esser)Added missing open_basedir & safe_mode checks to zip:// and bzip:// wrappers. (MOPB-21 by Stefan Esser).Fixed CRLF injection inside ftp_putcmd(). (by loveshell[at]Bug.Center.Team)Fixed a remotely trigger-able buffer overflow inside bundled libxmlrpc library. (by Stanislav Malyshev)Security Enhancements and Fixes in PHP 5.2.2 only:Fixed a header injection via Subject and To parameters to the mail() function (MOPB-34 by Stefan Esser)Fixed wrong length calculation in unserialize S type (MOPB-29 by Stefan Esser)Fixed substr_compare and substr_count information leak (MOPB-14 by Stefan Esser) (Stas, Ilia)Fixed a remotely trigger-able buffer overflow inside make_http_soap_request(). (by Ilia Alshanetsky)Fixed a buffer overflow inside user_filter_factory_create(). (by Ilia Alshanetsky)Fixed a possible super-global overwrite inside import_request_variables(). (by Stefano Di Paola, Stefan Esser)Limit nesting level of input variables with max_input_nesting_level as fix for (MOPB-03 by Stefan Esser)Security Enhancements and Fixes in PHP 4.4.7 only:XSS in phpinfo() (MOPB-8 by Stefan Esser) While majority of the issues outlined above are local, in some circumstances given specific code paths they can be triggered externally. Therefor, we strongly recommend that if you use code utilizing the functions and extensions identified as having had vulnerabilities in them, you consider upgrading your PHP. For users upgrading to PHP 5.2 from PHP 5.0 and PHP 5.1, an upgrade guide is available here, detailing the changes between those releases and PHP 5.2.2. Update: May 4th; The PHP 4.4.7 Windows build was updated due to the faulty Apache2 module shipped with the originalUpdate: May 23th; By accident a couple of fixes where listed as fixed in both PHP 5.2.2 and 4.4.7 but where however only fixed in PHP 5.2.2. The PHP 4 ChangeLog was not affected.
Views: 20Submitted: 25th of February 2008Report Dead Link

   Go Back


Home Write for Us Advertising Add Link

2000-2008 ProgrammerTutorials.com  Privacy Policy


ProgrammerTutorials.com Hosted by StartLogic
Partners: JavaScript tutorials | Free Webmaster Tools | Free Layouts | Make Money Online
Online Casinos - join in the fun and excitement of playing at online casinos. reviews, guides and much more at top21casinos.com
Buy Electonics | Buy Camera & Photo Equipment | Wii & Playstation 3 Video Games | Buy DVD's and Music | BetterBuyShop.com