{"id":563,"date":"2015-03-19T00:32:42","date_gmt":"2015-03-19T00:32:42","guid":{"rendered":"http:\/\/www.muratyaman.co.uk\/wp\/?p=563"},"modified":"2020-04-01T12:03:17","modified_gmt":"2020-04-01T11:03:17","slug":"what-has-changed-since-php-5-5-3","status":"publish","type":"post","link":"https:\/\/www.muratyaman.co.uk\/blog\/index.php\/2015\/03\/what-has-changed-since-php-5-5-3\/","title":{"rendered":"WHAT HAS CHANGED SINCE PHP 5.5.3?"},"content":{"rendered":"<p>A LOT!<\/p>\n<p><a href=\"http:\/\/www.muratyaman.co.uk\/wp\/wp-content\/uploads\/2015\/03\/bugs.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.muratyaman.co.uk\/wp\/wp-content\/uploads\/2015\/03\/bugs-300x235.jpg\" alt=\"bugs\" width=\"300\" height=\"235\" class=\"aligncenter size-medium wp-image-564\" srcset=\"https:\/\/www.muratyaman.co.uk\/blog\/wp-content\/uploads\/2015\/03\/bugs-300x235.jpg 300w, https:\/\/www.muratyaman.co.uk\/blog\/wp-content\/uploads\/2015\/03\/bugs.jpg 703w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>From: <a href=\"http:\/\/www.charliebaird.co.uk\/bugs_2000.htm\">http:\/\/www.charliebaird.co.uk\/bugs_2000.htm<\/a><\/p>\n<p>Bugs are not always cute. So, we need to upgrade all software applications we use on a regular basis.<\/p>\n<p>Ref: <a href=\"http:\/\/php.net\/ChangeLog-5.php\" title=\"PHP5 Change Log\">php.net\/ChangeLog-5.php<\/a><\/p>\n<p>Version 5.5.22<br \/>\n19-Feb-2015<\/p>\n<p>    Core:<br \/>\n        Fixed bug #67068 (getClosure returns somethings that&#8217;s not a closure).<br \/>\n        Fixed bug #68925 (Mitigation for CVE-2015-0235 \u2013 GHOST: glibc gethostbyname buffer overflow).<br \/>\n        Fixed bug #68942 (Use after free vulnerability in unserialize() with DateTimeZone). (CVE-2015-0273)<br \/>\n        Added NULL byte protection to exec, system and passthru.<br \/>\n        Removed support for multi-line headers, as they are deprecated by RFC 7230.<br \/>\n    Date:<br \/>\n        Fixed bug #45081 (strtotime incorrectly interprets SGT time zone).<br \/>\n    Dba:<br \/>\n        Fixed bug #68711 (useless comparisons).<br \/>\n    Enchant:<br \/>\n        Fixed bug #68552 (heap buffer overflow in enchant_broker_request_dict()).<br \/>\n    Fileinfo:<br \/>\n        Fixed bug #68827 (Double free with disabled ZMM).<br \/>\n    FPM:<br \/>\n        Fixed bug #66479 (Wrong response to FCGI_GET_VALUES).<br \/>\n        Fixed bug #68571 (core dump when webserver close the socket).<br \/>\n    Libxml:<br \/>\n        Fixed bug #64938 (libxml_disable_entity_loader setting is shared between threads).<br \/>\n    PDO_mysql:<br \/>\n        Fixed bug #68750 (PDOMysql with mysqlnd does not allow the usage of named pipes).<br \/>\n    Phar:<br \/>\n        Fixed bug #68901 (use after free).<br \/>\n    Pgsql:<br \/>\n        Fixed bug #65199 (pg_copy_from() modifies input array variable).<br \/>\n    Sqlite3:<br \/>\n        Fixed bug #68260 (SQLite3Result::fetchArray declares wrong required_num_args).<br \/>\n    Mysqli:<br \/>\n        Fixed bug #68114 (linker error on some OS X machines with fixed width decimal support).<br \/>\n        Fixed bug #68657 (Reading 4 byte floats with Mysqli and libmysqlclient has rounding errors).<br \/>\n    Session:<br \/>\n        Fixed bug #68941 (mod_files.sh is a bash-script).<br \/>\n        Fixed bug #66623 (no EINTR check on flock).<br \/>\n        Fixed bug #68063 (Empty session IDs do still start sessions).<br \/>\n    Standard:<br \/>\n        Fixed bug #65272 (flock() out parameter not set correctly in windows).<br \/>\n        Fixed bug #69033 (Request may get env. variables from previous requests if PHP works as FastCGI).<br \/>\n    Streams:<br \/>\n        Fixed bug which caused call after final close on streams filter.<\/p>\n<p>Version 5.5.21<br \/>\n22 Jan 2015<\/p>\n<p>    Core:<br \/>\n        Upgraded crypt_blowfish to version 1.3.<br \/>\n        Fixed bug #60704 (unlink() bug with some files path).<br \/>\n        Fixed bug #65419 (Inside trait, self::class != __CLASS__).<br \/>\n        Fixed bug #65576 (Constructor from trait conflicts with inherited constructor).<br \/>\n        Fixed bug #55541 (errors spawn MessageBox, which blocks test automation).<br \/>\n        Fixed bug #68297 (Application Popup provides too few information).<br \/>\n        Fixed bug #65769 (localeconv() broken in TS builds).<br \/>\n        Fixed bug #65230 (setting locale randomly broken).<br \/>\n        Fixed bug #66764 (configure doesn&#8217;t define EXPANDED_DATADIR \/ PHP_DATADIR correctly).<br \/>\n        Fixed bug #68583 (Crash in timeout thread).<br \/>\n        Fixed bug #68676 (Explicit Double Free). (CVE-2014-9425)<br \/>\n        Fixed bug #68710 (Use After Free Vulnerability in PHP&#8217;s unserialize()). (CVE-2015-0231)<br \/>\n    CGI:<br \/>\n        Fixed bug #68618 (out of bounds read crashes php-cgi). (CVE-2014-9427)<br \/>\n    CLI server:<br \/>\n        Fixed bug #68745 (Invalid HTTP requests make web server segfault).<br \/>\n    cURL:<br \/>\n        Fixed bug #67643 (curl_multi_getcontent returns &#8221; when CURLOPT_RETURNTRANSFER isn&#8217;t set).<br \/>\n    EXIF:<br \/>\n        Fixed bug #68799 (Free called on unitialized pointer). (CVE-2015-0232)<br \/>\n    Fileinfo:<br \/>\n        Fixed bug #68671 (incorrect expression in libmagic).<br \/>\n        Fixed bug #68735 (fileinfo out-of-bounds memory access).<br \/>\n        Removed readelf.c and related code from libmagic sources.<br \/>\n    FPM:<br \/>\n        Fixed bug #68751 (listen.allowed_clients is broken).<br \/>\n    GD:<br \/>\n        Fixed bug #68601 (buffer read overflow in gd_gif_in.c).<br \/>\n    Mbstring:<br \/>\n        Fixed bug #68504 (&#8211;with-libmbfl configure option not present on Windows).<br \/>\n    Mcrypt:<br \/>\n        Fixed possible read after end of buffer and use after free.<br \/>\n    Opcache:<br \/>\n        Fixed bug #67111 (Memory leak when using &#8220;continue 2&#8221; inside two foreach loops).<br \/>\n    OpenSSL:<br \/>\n        Fixed bug #55618 (use case-insensitive cert name matching).<br \/>\n    Pcntl:<br \/>\n        Fixed bug #60509 (pcntl_signal doesn&#8217;t decrease ref-count of old handler when setting SIG_DFL).<br \/>\n    PCRE:<br \/>\n        Fixed bug #66679 (Alignment Bug in PCRE 8.34 upstream).<br \/>\n    pgsql:<br \/>\n        Fixed bug #68697 (lo_export return -1 on failure).<br \/>\n    PDO:<br \/>\n        Fixed bug #68371 (PDO#getAttribute() cannot be called with platform-specific attribute names).<br \/>\n    PDO_mysql:<br \/>\n        Fixed bug #68424 (Add new PDO mysql connection attr to control multi statements option).<br \/>\n    SPL:<br \/>\n        Fixed bug #66405 (RecursiveDirectoryIterator::CURRENT_AS_PATHNAME breaks the RecursiveIterator).<br \/>\n        Fixed bug #65213 (cannot cast SplFileInfo to boolean).<br \/>\n        Fixed bug #68479 (Added escape parameter to SplFileObject::fputcsv).<br \/>\n    SQLite:<br \/>\n        Fixed bug #68120 (Update bundled libsqlite to 3.8.7.2).<br \/>\n    Streams:<br \/>\n        Fixed bug #68532 (convert.base64-encode omits padding bytes).<\/p>\n<p>Version 5.5.20<br \/>\n18 Dec 2014<\/p>\n<p>    Core:<br \/>\n        Fixed bug #68091 (Some Zend headers lack appropriate extern &#8220;C&#8221; blocks).<br \/>\n        Fixed bug #68185 (&#8220;Inconsistent insteadof definition.&#8221;- incorrectly triggered).<br \/>\n        Fixed bug #68370 (&#8220;unset($this)&#8221; can make the program crash).<br \/>\n        Fixed bug #68545 (NULL pointer dereference in unserialize.c).<br \/>\n        Fixed bug #68594 (Use after free vulnerability in unserialize()). (CVE-2014-8142)<br \/>\n    Date:<br \/>\n        Fixed day_of_week function as it could sometimes return negative values internally.<br \/>\n    FPM:<br \/>\n        Fixed bug #68381 (fpm_unix_init_main ignores log_level).<br \/>\n        Fixed bug #68420 (listen=9000 listens to ipv6 localhost instead of all addresses).<br \/>\n        Fixed bug #68421 (access.format=&#8217;%R&#8217; doesn&#8217;t log ipv6 address).<br \/>\n        Fixed bug #68423 (PHP-FPM will no longer load all pools).<br \/>\n        Fixed bug #68428 (listen.allowed_clients is IPv4 only).<br \/>\n        Fixed bug #68452 (php-fpm man page is oudated).<br \/>\n        Fixed bug #68458 (Change pm.start_servers default warning to notice).<br \/>\n        Fixed bug #68463 (listen.allowed_clients can silently result in no allowed access).<br \/>\n        Fixed bug #68391 (php-fpm conf files loading order).<br \/>\n        Fixed bug #68478 (access.log don&#8217;t use prefix).<br \/>\n    Mcrypt:<br \/>\n        Fixed possible read after end of buffer and use after free.<br \/>\n    PDO_pgsql:<br \/>\n        Fixed bug #66584 (Segmentation fault on statement deallocation).<br \/>\n        Fixed bug #67462 (PDO_PGSQL::beginTransaction() wrongly throws exception when not in transaction).<br \/>\n        Fixed bug #68351 (PDO::PARAM_BOOL and ATTR_EMULATE_PREPARES misbehaving).<br \/>\n    SOAP:<br \/>\n        Fixed bug #68361 (Segmentation fault on SoapClient::__getTypes).<br \/>\n    zlib:<br \/>\n        Fixed bug #53829 (Compiling PHP with large file support will replace function gzopen by gzopen64).<\/p>\n<p>Version 5.5.19<br \/>\n13 Nov 2014<\/p>\n<p>    Core:<br \/>\n        Fixed bug #68095 (AddressSanitizer reports a heap buffer overflow in php_getopt()).<br \/>\n        Fixed bug #68118 ($a->foo .= &#8216;test&#8217;; can leave $a->foo undefined).<br \/>\n        Fixed bug #68129 (parse_url() &#8211; incomplete support for empty usernames and passwords).<br \/>\n        Fixed bug #68365 (zend_mm_heap corrupted after memory overflow in zend_hash_copy).<br \/>\n    cURL:<br \/>\n        Add CURL_SSLVERSION_TLSv1_0, CURL_SSLVERSION_TLSv1_1, and CURL_SSLVERSION_TLSv1_2 constants if supported by libcurl.<br \/>\n    Fileinfo:<br \/>\n        Fixed bug #66242 (libmagic: don&#8217;t assume char is signed).<br \/>\n        Fixed bug #68283 (fileinfo: out-of-bounds read in elf note headers). (CVE-2014-3710)<br \/>\n    FPM:<br \/>\n        Implemented FR #55508 (listen and listen.allowed_clients should take IPv6 addresses.<br \/>\n    GD:<br \/>\n        Fixed bug #65171imagescale() fails without height param<br \/>\n    GMP:<br \/>\n        Fixed bug #63595 (GMP memory management conflicts with other libraries using GMP).<br \/>\n    Mysqli:<br \/>\n        Fixed bug #68114 (linker error on some OS X machines with fixed width decimal support).<br \/>\n    ODBC:<br \/>\n        Fixed bug #68087 (ODBC not correctly reading DATE column when preceded by a VARCHAR column)<br \/>\n    SPL:<br \/>\n        Fixed bug #68128 (Regression in RecursiveRegexIterator)<\/p>\n<p>Version 5.5.18<br \/>\n16 Oct 2014<\/p>\n<p>    Core:<br \/>\n        Fixed bug #67985 (Incorrect last used array index copied to new array after unset).<br \/>\n        Fixed bug #67739 (Windows 8.1\/Server 2012 R2 OS build number reported as 6.2 (instead of 6.3)).<br \/>\n        Fixed bug #67633 (A foreach on an array returned from a function not doing copy-on-write).<br \/>\n        Fixed bug #51800 (proc_open on Windows hangs forever).<br \/>\n        Fixed bug #68044 (Integer overflow in unserialize() (32-bits only)). (CVE-2014-3669)<br \/>\n    cURL:<br \/>\n        Fixed bug #68089 (NULL byte injection &#8211; cURL lib).<br \/>\n    Exif:<br \/>\n        Fixed bug #68113 (Heap corruption in exif_thumbnail()). (CVE-2014-3670)<br \/>\n    FPM:<br \/>\n        Fixed bug #65641 (PHP-FPM incorrectly defines the SCRIPT_NAME variable when using Apache, mod_proxy-fcgi and ProxyPass).<br \/>\n    OpenSSL:<br \/>\n        Revert regression introduced by fix of bug #41631.<br \/>\n    Reflection:<br \/>\n        Fixed bug #68103 (Duplicate entry in Reflection for class alias).<br \/>\n    Session:<br \/>\n        Fixed bug #67972 (SessionHandler Invalid memory read create_sid()).<br \/>\n    XMLRPC:<br \/>\n        Fixed bug #68027 (Global buffer overflow in mkgmtime() function). (CVE-2014-3668)<\/p>\n<p>Version 5.5.17<br \/>\n18 Sep 2014<\/p>\n<p>    Core:<br \/>\n        Fixed bug #47358 (glob returns error, should be empty array()).<br \/>\n        Fixed bug #65463 (SIGSEGV during zend_shutdown()).<br \/>\n        Fixed bug #66036 (Crash on SIGTERM in apache process).<br \/>\n        Fixed bug #67878 (program_prefix not honoured in man pages).<br \/>\n    COM:<br \/>\n        Fixed bug #41577 (DOTNET is successful once per server run).<br \/>\n    Date:<br \/>\n        Fixed bug #66091 (memory leaks in DateTime constructor).<br \/>\n        Fixed bug #66985 (Some timezones are no longer valid in PHP 5.5.10).<br \/>\n        Fixed bug #67109 (First uppercase letter breaks date string parsing).<br \/>\n    FPM:<br \/>\n        Fixed bug #67606 (FPM with mod_fastcgi\/apache2.4 is broken).<br \/>\n    GD:<br \/>\n        Made fontFetch&#8217;s path parser thread-safe.<br \/>\n    MySQLi:<br \/>\n        Fixed bug #67839 (mysqli does not handle 4-byte floats correctly).<br \/>\n    OpenSSL:<br \/>\n        Fixed bug #41631 (socket timeouts not honored in blocking SSL reads).<br \/>\n        Fixed bug #67850 (extension won&#8217;t build if openssl compiled without SSLv3).<br \/>\n    SPL:<br \/>\n        Fixed bug #67813 (CachingIterator::__construct InvalidArgumentException wrong message).<br \/>\n    Zlib:<br \/>\n        Fixed bug #67724 (chained zlib filters silently fail with large amounts of data).<br \/>\n        Fixed bug #67865 (internal corruption phar error).<\/p>\n<p>Version 5.5.16<br \/>\n21 Aug 2014<\/p>\n<p>    COM:<br \/>\n        Fixed missing type checks in com_event_sink.<br \/>\n    Core:<br \/>\n        Fixed bug #67693 (incorrect push to the empty array).<br \/>\n    Fileinfo:<br \/>\n        Fixed bug #67705 (extensive backtracking in rule regular expression). (CVE-2014-3538).<br \/>\n        Fixed bug #67716 (Segfault in cdf.c). (CVE-2014-3587).<br \/>\n    FPM:<br \/>\n        Fixed bug #67635 (php links to systemd libraries without using pkg-config).<br \/>\n    GD:<br \/>\n        Fixed bug #66901 (php-gd &#8216;c_color&#8217; NULL pointer dereference). (CVE-2014-2497).<br \/>\n        Fixed bug #67730 (Null byte injection possible with imagexxx functions). (CVE-2014-5120).<br \/>\n    Milter:<br \/>\n        Fixed bug #67715 (php-milter does not build and crashes randomly).<br \/>\n    Network:<br \/>\n        Fixed bug #67717 (segfault in dns_get_record). (CVE-2014-3597).<br \/>\n    OpenSSL:<br \/>\n        Fixed missing type checks in OpenSSL options.<br \/>\n    readline:<br \/>\n        Fixed bug #55496 (Interactive mode doesn&#8217;t force a newline before the prompt).<br \/>\n        Fixed bug #67496 (Save command history when exiting interactive shell with control-c).<br \/>\n    Sessions:<br \/>\n        Fixed missing type checks in php_session_create_id.<br \/>\n    ODBC:<br \/>\n        Fixed bug #60616 (odbc_fetch_into returns junk data at end of multi-byte char fields).<\/p>\n<p>Version 5.5.15<br \/>\n24 Jul 2014<\/p>\n<p>    CLI server:<br \/>\n        Fixed bug #67429 (CLI server is missing some new HTTP response codes).<br \/>\n        Fixed bug #66830 (Empty header causes PHP built-in web server to hang).<br \/>\n    Core:<br \/>\n        Fixed bug #67428 (header(&#8216;Location: foo&#8217;) will override a 308-399 response code).<br \/>\n        Fixed bug #67436 (Autoloader isn&#8217;t called if two method definitions don&#8217;t match).<br \/>\n        Fixed bug #67091 (make install fails to install libphp5.so on FreeBSD 10.0).<br \/>\n        Fixed bug #67497 eval with parse error causes segmentation fault in generator).<br \/>\n        Fixed bug #67151 (strtr with empty array crashes).<br \/>\n        Fixed bug #67407 (Windows 8.1\/Server 2012 R2 reported as Windows 8\/Server 2012).<br \/>\n    FPM:<br \/>\n        Fixed bug #67530 (error_log=syslog ignored).<br \/>\n        Fixed bug #67531 (syslog cannot be set in pool configuratio).<br \/>\n    Intl:<br \/>\n        Fixed bug #66921 (Wrong argument type hint for function intltz_from_date_time_zone).<br \/>\n        Fixed bug #67052 (NumberFormatter::parse() resets LC_NUMERIC setting).<br \/>\n    OPCache:<br \/>\n        Fixed bug #67215 (php-cgi work with opcache, may be segmentation fault happen).<br \/>\n    pgsql:<br \/>\n        Fixed bug #67550 (Error in code &#8220;form&#8221; instead of &#8220;from&#8221;, pgsql.c, line 756), which affected builds against libpq < 7.3).\n    Phar:\n        Fixed bug #67587 (Redirection loop on nginx with FPM).\n    SPL:\n        Fixed bug #67539 (ArrayIterator use-after-free due to object change during sorting). (CVE-2014-4698)\n        Fixed bug #67538 (SPL Iterators use-after-free) (CVE-2014-4670).\n    Streams:\n        Fixed bug #67430 (http:\/\/ wrapper doesn't follow 308 redirects).\n\nVersion 5.5.14\n26 Jun 2014\n\n    CLI server:\n        Fixed bug #67406 (built-in web-server segfaults on startup).\n    Core:\n        Fixed bug #66622 (Closures do not correctly capture the late bound class (static::) in some cases).\n        Fixed bug #67390 (insecure temporary file use in the configure script). (CVE-2014-3981).\n        Fixed bug #67399 (putenv with empty variable may lead to crash).\n        Fixed bug #67498 (phpinfo() Type Confusion Information Leak Vulnerability).\n        Fixed BC break introduced by patch for bug #67072.\n    Date:\n        Fixed bug #67308 (Serialize of DateTime truncates fractions of second).\n        Fixed regression in fix for bug #67118 (constructor can't be called twice).\n    Fileinfo:\n        Fixed bug #67326 (cdf_read_short_sector insufficient boundary check). (CVE-2014-0207)).\n        Fixed bug #67410 (mconvert incorrect handling of truncated pascal string size). (CVE-2014-3478).\n        Fixed bug #67411 (cdf_check_stream_offset insufficient boundary check). (CVE-2014-3479).\n        Fixed bug #67412 (cdf_count_chain insufficient boundary check). (CVE-2014-3480).\n        Fixed bug #67413 (cdf_read_property_info insufficient boundary check). (CVE-2014-3487).\n    Intl:\n        Fixed bug #67349 (Locale::parseLocale Double Free).\n        Fixed bug #67397 (Buffer overflow in locale_get_display_name and uloc_getDisplayName (libicu 4.8.1)).\n    Network:\n        Fixed bug #67432 (Fix potential segfault in dns_get_record()). (CVE-2014-4049)).\n    OPCache:\n        Fixed issue #183 (TMP_VAR is not only used once).\n    OpenSSL:\n        Fixed bug #65698 (certificates validity parsing does not work past 2050).\n        Fixed bug #66636 (openssl_x509_parse warning with V_ASN1_GENERALIZEDTIME).\n    PDO-ODBC:\n        Fixed bug #50444 (PDO-ODBC changes for 64-bit).\n    SOAP:\n        Implemented FR #49898 (Add SoapClient::__getCookies()).\n    SPL:\n        Fixed bug #66127 (Segmentation fault with ArrayObject unset).\n        Fixed bug #67359 (Segfault in recursiveDirectoryIterator).\n        Fixed bug #67360 (Missing element after ArrayObject::getIterator).\n        Fixed bug #67492 (unserialize() SPL ArrayObject \/ SPLObjectStorage Type Confusion). (CVE-2014-3515).\n\nVersion 5.5.13\n29 May 2014\n\n    CLI server:\n        Fixed bug #67079 (Missing MIME types for XML\/XSL files).\n    COM:\n        Fixed bug #66431 (Special Character via COM Interface (CP_UTF8)).\n    Core:\n        Fixed bug #65701 (copy() doesn't work when destination filename is created by tempnam()).\n        Fixed bug #67072 (Echoing unserialized \"SplFileObject\" crash).\n        Fixed bug #67245 (usage of memcpy() with overlapping src and dst in zend_exceptions.c).\n        Fixed bug #67247 (spl_fixedarray_resize integer overflow).\n        Fixed bug #67249 (printf out-of-bounds read).\n        Fixed bug #67250 (iptcparse out-of-bounds read).\n    cURL:\n        Fixed bug #64247 (CURLOPT_INFILE doesn't allow reset).\n    Date:\n        Fixed bug #67118 (DateTime constructor crash with invalid data).\n        Fixed bug #67251 (date_parse_from_format out-of-bounds read).\n        Fixed bug #67253 (timelib_meridian_with_check out-of-bounds read).\n    DOM:\n        Fixed bug #67081 (DOMDocumentType->internalSubset returns entire DOCTYPE tag, not only the subset).<br \/>\n    Fileinfo:<br \/>\n        Fixed bug #66307 (Fileinfo crashes with powerpoint files).<br \/>\n        Fixed bug #67327 (CDF infinite loop in nelements DoS) (CVE-2014-0238).<br \/>\n        Fixed bug #67328 (numerous file_printf calls resulting in performance degradation) (CVE-2014-0237).<br \/>\n    FPM:<br \/>\n        Fixed bug #66908 (php-fpm reload leaks epoll_create() file descriptor).<br \/>\n    GD:<br \/>\n        Fixed bug #67248 (imageaffinematrixget missing check of parameters).<br \/>\n    PCRE:<br \/>\n        Fixed bug #67248 Ungreedy and min\/max quantifier bug, applied patch from the upstream.<br \/>\n    Phar:<br \/>\n        Fixed bug #64498 ($phar->buildFromDirectory can&#8217;t compress file with an accent in its name).<\/p>\n<p>Version 5.5.12<br \/>\n01 May 2014<\/p>\n<p>    Core:<br \/>\n        Fixed bug #61019 (Out of memory on command stream_get_contents).<br \/>\n        Fixed bug #64330 (stream_socket_server() creates wrong Abstract Namespace UNIX sockets).<br \/>\n        Fixed bug #66182 (exit in stream filter produces segfault).<br \/>\n        Fixed bug #66736 (fpassthru broken).<br \/>\n        Fixed bug #67024 (getimagesize should recognize BMP files with negative heighty).<br \/>\n        Fixed bug #67043 (substr_compare broke by previous change).<br \/>\n    cURL:<br \/>\n        Fixed bug #66562 (curl_exec returns differently than curl_multi_getcontent).<br \/>\n    Date:<br \/>\n        Fixed bug #66721 (__wakeup of DateTime segfaults when invalid object data is supplied).<br \/>\n    Embed:<br \/>\n        Fixed bug #65715 (php5embed.lib isn&#8217;t provided anymore).<br \/>\n    Fileinfo:<br \/>\n        Fixed bug #66987 (Memory corruption in fileinfo ext \/ bigendian).<br \/>\n    FPM:<br \/>\n        Fixed bug #66482 (unknown entry &#8216;priority&#8217; in php-fpm.conf).<br \/>\n        Fixed bug #67060 (possible privilege escalation due to insecure default configuration). (CVE-2014-0185)).<br \/>\n    Json:<br \/>\n        Fixed bug #66021 (Blank line inside empty array\/object when JSON_PRETTY_PRINT is set).<br \/>\n    LDAP:<br \/>\n        Fixed issue with null bytes in LDAP bindings.<br \/>\n    mysqli:<br \/>\n        Fixed problem in mysqli_commit()\/mysqli_rollback() with second parameter (extra comma) and third parameters (lack of escaping).<br \/>\n    Openssl:<br \/>\n        Fixed bug #66942 (memory leak in openssl_seal()).<br \/>\n        Fixed bug #66952 (memory leak in openssl_open()).<br \/>\n    SimpleXML:<br \/>\n        Fixed bug #66084 (simplexml_load_string() mangles empty node name).<br \/>\n    SQLite:<br \/>\n        Fixed bug #66967 (Updated bundled libsqlite to 3.8.4.3)<br \/>\n    XSL:<br \/>\n        Fixed bug #53965 (<xsl:include> cannot find files with relative paths when loaded with &#8220;file:\/\/&#8221;)<br \/>\n    Apache2 Handler SAPI:<br \/>\n        Fixed Apache log issue caused by APR&#8217;s lack of support for %zu (APR issue https:\/\/issues.apache.org\/bugzilla\/show_bug.cgi?id=56120)<\/p>\n<p>Version 5.5.12<br \/>\n01 May 2014<\/p>\n<p>    Core:<br \/>\n        Fixed bug #61019 (Out of memory on command stream_get_contents).<br \/>\n        Fixed bug #64330 (stream_socket_server() creates wrong Abstract Namespace UNIX sockets).<br \/>\n        Fixed bug #66182 (exit in stream filter produces segfault).<br \/>\n        Fixed bug #66736 (fpassthru broken).<br \/>\n        Fixed bug #67024 (getimagesize should recognize BMP files with negative heighty).<br \/>\n        Fixed bug #67043 (substr_compare broke by previous change).<br \/>\n    cURL:<br \/>\n        Fixed bug #66562 (curl_exec returns differently than curl_multi_getcontent).<br \/>\n    Date:<br \/>\n        Fixed bug #66721 (__wakeup of DateTime segfaults when invalid object data is supplied).<br \/>\n    Embed:<br \/>\n        Fixed bug #65715 (php5embed.lib isn&#8217;t provided anymore).<br \/>\n    Fileinfo:<br \/>\n        Fixed bug #66987 (Memory corruption in fileinfo ext \/ bigendian).<br \/>\n    FPM:<br \/>\n        Fixed bug #66482 (unknown entry &#8216;priority&#8217; in php-fpm.conf).<br \/>\n        Fixed bug #67060 (possible privilege escalation due to insecure default configuration). (CVE-2014-0185)).<br \/>\n    Json:<br \/>\n        Fixed bug #66021 (Blank line inside empty array\/object when JSON_PRETTY_PRINT is set).<br \/>\n    LDAP:<br \/>\n        Fixed issue with null bytes in LDAP bindings.<br \/>\n    mysqli:<br \/>\n        Fixed problem in mysqli_commit()\/mysqli_rollback() with second parameter (extra comma) and third parameters (lack of escaping).<br \/>\n    Openssl:<br \/>\n        Fixed bug #66942 (memory leak in openssl_seal()).<br \/>\n        Fixed bug #66952 (memory leak in openssl_open()).<br \/>\n    SimpleXML:<br \/>\n        Fixed bug #66084 (simplexml_load_string() mangles empty node name).<br \/>\n    SQLite:<br \/>\n        Fixed bug #66967 (Updated bundled libsqlite to 3.8.4.3)<br \/>\n    XSL:<br \/>\n        Fixed bug #53965 (<xsl:include> cannot find files with relative paths when loaded with &#8220;file:\/\/&#8221;)<br \/>\n    Apache2 Handler SAPI:<br \/>\n        Fixed Apache log issue caused by APR&#8217;s lack of support for %zu (APR issue https:\/\/issues.apache.org\/bugzilla\/show_bug.cgi?id=56120)<\/p>\n<p>Version 5.5.11<br \/>\n03 Apr 2014<\/p>\n<p>    Core:<br \/>\n        Fixed bug #60602 (proc_open() changes environment array).<br \/>\n        Allow zero length comparison in substr_compare().<br \/>\n    cURL:<br \/>\n        Fixed bug #66109 (Can&#8217;t reset CURLOPT_CUSTOMREQUEST to default behaviour).<br \/>\n        Fix compilation on libcurl versions between 7.10.5 and 7.12.2, inclusive.<br \/>\n    Fileinfo:<br \/>\n        Fixed bug #66946 (fileinfo: extensive backtracking in awk rule regular expression (CVE-2013-7345)).<br \/>\n    FPM:<br \/>\n        Added clear_env configuration directive to disable clearenv() call.<br \/>\n    GD:<br \/>\n        Fixed bug #66714 (imageconvolution breakage).<br \/>\n        Fixed bug #66869 (Invalid 2nd argument crashes imageaffinematrixget).<br \/>\n        Fixed bug #66887 (imagescale &#8211; poor quality of scaled image).<br \/>\n        Fixed bug #66890 (imagescale segfault).<br \/>\n        Fixed bug #66893 (imagescale ignore method argument).<br \/>\n    GMP:<br \/>\n        Fixed bug #66872 (invalid argument crashes gmp_testbit).<br \/>\n    Hash:<br \/>\n        hash_pbkdf2() now works correctly if the $length argument is not specified.<br \/>\n    Intl:<br \/>\n        Fixed bug #66873 A reproductible crash in UConverter when given invalid encoding.<br \/>\n    Mail:<br \/>\n        Fixed bug #66535 (Don&#8217;t add newline after X-PHP-Originating-Script).<br \/>\n    MySQLi:<br \/>\n        Fixed bug #66762 (Segfault in mysqli_stmt::bind_result() when link closed).<br \/>\n    OPCache:<br \/>\n        Added function opcache_is_script_cached().<br \/>\n        Added information about interned strings usage.<br \/>\n    Openssl:<br \/>\n        Fixed bug #66833 (Default disgest algo is still MD5, switch to SHA1).<br \/>\n    SQLite:<br \/>\n        Updated bundled libsqlite to 3.8.3.1.<br \/>\n    SPL:<br \/>\n        Added feature #65545 (SplFileObject::fread()).<\/p>\n<p>Version 5.5.10<br \/>\n06 Mar 2014<\/p>\n<p>    Core:<br \/>\n        Fixed bug #66574 (Allow multiple paths in php_ini_scanned_path).<br \/>\n    Date:<br \/>\n        Fixed bug #45528 (Allow the DateTimeZone constructor to accept timezones per offset too).<br \/>\n    Fileinfo:<br \/>\n        Fixed bug #66731 (file: infinite recursion (CVE-2014-1943)).<br \/>\n        Fixed bug #66820 (out-of-bounds memory access in fileinfo (CVE-2014-2270)).<br \/>\n    GD:<br \/>\n        Fixed bug #66815 (imagecrop(): insufficient fix for NULL defer (CVE-2013-7327)).<br \/>\n    JSON:<br \/>\n        Fixed bug #65753 (JsonSerializeable couldn&#8217;t implement on module extension).<br \/>\n    LDAP:<br \/>\n        Implemented ldap_modify_batch (https:\/\/wiki.php.net\/rfc\/ldap_modify_batch).<br \/>\n    Openssl:<br \/>\n        Fixed bug #66501 (Add EC key support to php_openssl_is_private_key).<br \/>\n    PCRE:<br \/>\n        Upgraded to PCRE 8.34.<br \/>\n    Pgsql:<br \/>\n        Added warning for dangerous client encoding and remove possible injections for pg_insert()\/pg_update()\/pg_delete()\/pg_select().<\/p>\n<p>Version 5.5.9<br \/>\n06 Feb 2014<\/p>\n<p>    Core:<br \/>\n        Fixed bug #66509 (copy() arginfo has changed starting from 5.4).<br \/>\n    GD:<br \/>\n        Fixed bug #66356 (Heap Overflow Vulnerability in imagecrop(), CVE-2013-7226).<br \/>\n    OPCache:<br \/>\n        Fixed bug #66474 (Optimizer bug in constant string to boolean conversion).<br \/>\n        Fixed bug #66461 (PHP crashes if opcache.interned_strings_buffer=0).<br \/>\n        Fixed bug #66298 (ext\/opcache\/Optimizer\/zend_optimizer.c has dos-style ^M as lineend).<br \/>\n    PDO_pgsql:<br \/>\n        Fixed bug #62479 (PDO-pgsql cannot connect if password contains spaces).<br \/>\n    Readline:<br \/>\n        Fixed bug #66412 (readline_clear_history() with libedit causes segfault after #65714).<br \/>\n    Session:<br \/>\n        Fixed bug #66469 (Session module is sending multiple set-cookie headers when session.use_strict_mode=1).<br \/>\n        Fixed bug #66481 (Segfaults on session_name()).<br \/>\n    Standard:<br \/>\n        Fixed bug #66395 (basename function doesn&#8217;t remove drive letter).<br \/>\n    Sockets:<br \/>\n        Fixed bug #66381 (__ss_family was changed on AIX 5.3).<br \/>\n    Zend Engine:<br \/>\n        Fixed bug #66009 (Failed compilation of PHP extension with C++ std library using VS 2012).<\/p>\n<p>Version 5.4.25<br \/>\n06 Feb 2014<\/p>\n<p>    Core:<br \/>\n        Fixed bug #66286 (Incorrect object comparison with inheritance).<br \/>\n        Fixed bug #66509 (copy() arginfo has changed starting from 5.4).<br \/>\n    mysqlnd:<br \/>\n        Fixed bug #66283 (Segmentation fault after memory_limit).<br \/>\n    PDO_pgsql:<br \/>\n        Fixed bug #62479 (PDO-psql cannot connect if password contains spaces).<br \/>\n    Session:<br \/>\n        Fixed bug #66481 (Calls to session_name() segfault when session.name is null).<\/p>\n<p>Version 5.5.8<br \/>\n09 Jan 2014<\/p>\n<p>    Core:<br \/>\n        Disallowed JMP into a finally block.<br \/>\n        Added validation of class names in the autoload process.<br \/>\n        Fixed invalid C code in zend_strtod.c.<br \/>\n        Fixed bug #66041 (list() fails to unpack yielded ArrayAccess object).<br \/>\n        Fixed bug #65764 (generators\/throw_rethrow FAIL with ZEND_COMPILE_EXTENDED_INFO).<br \/>\n        Fixed bug #61645 (fopen and O_NONBLOCK).<br \/>\n        Fixed bug #66218 (zend_register_functions breaks reflection).<br \/>\n    Date:<br \/>\n        Fixed bug #66060 (Heap buffer over-read in DateInterval, CVE-2013-6712).<br \/>\n        Fixed bug #65768 (DateTimeImmutable::diff does not work).<br \/>\n    DOM:<br \/>\n        Fixed bug #65196 (Passing DOMDocumentFragment to DOMDocument::saveHTML() Produces invalid Markup).<br \/>\n    Exif:<br \/>\n        Fixed bug #65873 (Integer overflow in exif_read_data()).<br \/>\n    Filter:<br \/>\n        Fixed bug #66229 (128.0.0.0\/16 isn&#8217;t reserved any longer).<br \/>\n    GD:<br \/>\n        Fixed bug #64405 (Use freetype-config for determining freetype2 dir(s)).<br \/>\n    PDO_odbc:<br \/>\n        Fixed bug #66311 (Stack smashing protection kills PDO\/ODBC queries).<br \/>\n    MySQLi:<br \/>\n        Fixed bug #65486 (mysqli_poll() is broken on win x64).<br \/>\n    OPCache:<br \/>\n        Fixed revalidate_path=1 behavior to avoid caching of symlinks values.<br \/>\n        Fixed issue #140 (&#8220;opcache.enable_file_override&#8221; doesn&#8217;t respect &#8220;opcache.revalidate_freq&#8221;.)<br \/>\n    SNMP:<br \/>\n        Fixed SNMP_ERR_TOOBIG handling for bulk walk operations.<br \/>\n    SOAP:<br \/>\n        Fixed bug #66112 (Use after free condition in SOAP extension).<br \/>\n    Sockets:<br \/>\n        Fixed bug #65923 (ext\/socket assumes AI_V4MAPPED is defined).<br \/>\n    XSL:<br \/>\n        Fixed bug #49634 (Segfault throwing an exception in a XSL registered function).<br \/>\n    ZIP:<br \/>\n        Fixed bug #66321 (ZipArchive::open() ze_obj->filename_len not real).<\/p>\n<p>Version 5.5.7<br \/>\n12 Dec 2013<\/p>\n<p>    Core:<br \/>\n        Fixed bug #66094 (unregister_tick_function tries to cast a Closure to a string).<br \/>\n        Fixed bug #65969 (Chain assignment with T_LIST failure).<br \/>\n    CLI server:<br \/>\n        Added some MIME types to the CLI web server.<br \/>\n        Implemented FR #65917 (getallheaders() is not supported by the built-in web server) &#8211; also implements apache_response_headers()<br \/>\n    OPCache:<br \/>\n        Fixed bug #66176 (Invalid constant substitution).<br \/>\n        Fixed bug #65915 (Inconsistent results with require return value).<br \/>\n        Fixed bug #65559 (Opcache: cache not cleared if changes occur while running).<br \/>\n    readline:<br \/>\n        Fixed bug #65714 (PHP cli forces the tty to cooked mode).<br \/>\n    Openssl:<br \/>\n        Fixed memory corruption in openssl_x509_parse() (CVE-2013-6420).<\/p>\n<p>Version 5.5.6<br \/>\n14 Nov 2013<\/p>\n<p>    Core:<br \/>\n        Improved performance of array_merge() and func_get_args() by eliminating useless copying.<br \/>\n        Fixed bug #65947 (basename is no more working after fgetcsv in certain situation).<br \/>\n        Fixed bug #65939 (Space before &#8220;;&#8221; breaks php.ini parsing).<br \/>\n        Fixed bug #65911 (scope resolution operator &#8211; strange behavior with $this).<br \/>\n        Fixed bug #65936 (dangling context pointer causes crash).<br \/>\n    FPM:<br \/>\n        Changed default listen() backlog to 65535.<br \/>\n    JSON:<br \/>\n        Fixed bug #64874 (json_decode handles whitespace incorrectly).<br \/>\n    MySQLi:<br \/>\n        Fixed bug #66043 (Segfault calling bind_param() on mysqli).<br \/>\n    OPCache:<br \/>\n        Increased limit for opcache.max_accelerated_files to 1,000,000.<br \/>\n        Fixed issue #115 (path issue when using phar).<br \/>\n        Fixed issue #149 (Phar mount points not working with OPcache enabled).<br \/>\n    ODBC:<br \/>\n        Fixed bug #65950 (Field name truncation if the field name is bigger than 32 characters).<br \/>\n    PDO:<br \/>\n        Fixed bug #66033 (Segmentation Fault when constructor of PDO statement throws an exception).<br \/>\n        Fixed bug #65946 (sql_parser permanently converts values bound to strings).<br \/>\n    Standard:<br \/>\n        Fixed bug #64760 (var_export() does not use full precision for floating-point numbers).<\/p>\n<p>Version 5.5.5<br \/>\n17 Oct 2013<\/p>\n<p>    Core:<br \/>\n        Fixed bug #64979 (Wrong behavior of static variables in closure generators).<br \/>\n        Fixed bug #65322 (compile time errors won&#8217;t trigger auto loading).<br \/>\n        Fixed bug #65821 (By-ref foreach on property access of string offset segfaults).<br \/>\n    CLI Server:<br \/>\n        Fixed bug #65633 (built-in server treat some http headers as case-sensitive).<br \/>\n        Fixed bug #65818 (Segfault with built-in webserver and chunked transfer encoding).<br \/>\n        Added application\/pdf to PHP CLI Web Server mime types<br \/>\n    Datetime:<br \/>\n        Fixed bug #64157 (DateTime::createFromFormat() reports confusing error message).<br \/>\n        Fixed bug #65502 (DateTimeImmutable::createFromFormat returns DateTime).<br \/>\n        Fixed bug #65548 (Comparison for DateTimeImmutable doesn&#8217;t work).<br \/>\n    DBA:<br \/>\n        Fixed bug #65708 (dba functions cast $key param to string in-place, bypassing copy on write).<br \/>\n    Filter:<br \/>\n        Add RFC 6598 IPs to reserved addresses.<br \/>\n        Fixed bug #64441 (FILTER_VALIDATE_URL rejects fully qualified domain names).<br \/>\n    FTP:<br \/>\n        Fixed bug #65667 (ftp_nb_continue produces segfault).<br \/>\n    GD:<br \/>\n        Ensure that the defined interpolation method is used with the generic scaling methods.<br \/>\n    IMAP:<br \/>\n        Fixed bug #65721 (configure script broken in 5.5.4 and 5.4.20 when enabling imap).<br \/>\n    OPCache:<br \/>\n        Fixed bug #65845 (Error when Zend Opcache Optimizer is fully enabled).<br \/>\n        Fixed bug #65665 (Exception not properly caught when opcache enabled).<br \/>\n        Fixed bug #65510 (5.5.2 crashes in _get_zval_ptr_ptr_var).<br \/>\n        Fixed issue #135 (segfault in interned strings if initial memory is too low).<br \/>\n        Added function opcache_compile_file() to load PHP scripts into cache without execution.<br \/>\n        Added support for GNU Hurd.<br \/>\n    Sockets:<br \/>\n        Fixed bug #65808 (the socket_connect() won&#8217;t work with IPv6 address).<br \/>\n    SPL:<br \/>\n        Fixed bug #64782 (SplFileObject constructor make $context optional \/ give it a default value).<br \/>\n    Standard:<br \/>\n        Fixed bug #61548 content-type must appear at the end of headers for 201 Location to work in http.<br \/>\n    XMLReader:<br \/>\n        Fixed bug #51936 Crash with clone XMLReader.<br \/>\n        Fixed bug #64230 XMLReader does not suppress errors.<br \/>\n    Build system:<br \/>\n        Fixed bug #51076 Race condition in shtool&#8217;s mkdir -p implementation.<br \/>\n        Fixed bug #62396 &#8216;make test&#8217; crashes starting with 5.3.14 (missing gzencode()).<\/p>\n<p>Version 5.5.4<br \/>\n19 Sep 2013<\/p>\n<p>    Core:<br \/>\n        Fixed bug #60598 (cli\/apache sapi segfault on objects manipulation).<br \/>\n        Improved fputcsv() to allow specifying escape character.<br \/>\n        Fixed bug #65483 (quoted-printable encode stream filter incorrectly encoding spaces).<br \/>\n        Fixed bug #65470 (Segmentation fault in zend_error() with &#8211;enable-dtrace).<br \/>\n        Fixed bug #65490 (Duplicate calls to get lineno &#038; filename for DTRACE_FUNCTION_*).<br \/>\n        Fixed bug #65225 (PHP_BINARY incorrectly set).<br \/>\n        Fixed bug #62692 (PHP fails to build with DTrace).<br \/>\n        Fixed bug #61759 (class_alias() should accept classes with leading backslashes).<br \/>\n        Fixed bug #46311 (Pointer aliasing issue results in miscompile on gcc4.4).<br \/>\n    cURL:<br \/>\n        Fixed bug #65458 (curl memory leak).<br \/>\n    Datetime:<br \/>\n        Fixed bug #65554 (createFromFormat broken when weekday name is followed by some delimiters).<br \/>\n        Fixed bug #65564 (stack-buffer-overflow in DateTimeZone stuff caught by AddressSanitizer).<br \/>\n    OPCache:<br \/>\n        Fixed bug #65561 (Zend Opcache on Solaris 11 x86 needs ZEND_MM_ALIGNMENT=4).<br \/>\n    Openssl:<br \/>\n        Fixed bug #64802 (openssl_x509_parse fails to parse subject properly in some cases).<br \/>\n    Session:<br \/>\n        Fixed bug #65475 (Session ID is not initialized properly when strict session is enabled).<br \/>\n        Fixed bug #51127 and #65359, FR #25630\/#43980\/#54383 (Added php_serialize session serialize handler that uses plain serialize())<br \/>\n    Standard:<br \/>\n        Fix issue with return types of password API helper functions. Found via static analysis by cjones.<\/p>\n<p>Version 5.5.3<br \/>\n22 Aug 2013<\/p>\n<p>    Openssl:<br \/>\n        Fixed UMR in fix for CVE-2013-4248.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A LOT!<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[26,129],"class_list":["post-563","post","type-post","status-publish","format-standard","hentry","category-technology","tag-php","tag-vcs"],"_links":{"self":[{"href":"https:\/\/www.muratyaman.co.uk\/blog\/index.php\/wp-json\/wp\/v2\/posts\/563","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.muratyaman.co.uk\/blog\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.muratyaman.co.uk\/blog\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.muratyaman.co.uk\/blog\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.muratyaman.co.uk\/blog\/index.php\/wp-json\/wp\/v2\/comments?post=563"}],"version-history":[{"count":3,"href":"https:\/\/www.muratyaman.co.uk\/blog\/index.php\/wp-json\/wp\/v2\/posts\/563\/revisions"}],"predecessor-version":[{"id":911,"href":"https:\/\/www.muratyaman.co.uk\/blog\/index.php\/wp-json\/wp\/v2\/posts\/563\/revisions\/911"}],"wp:attachment":[{"href":"https:\/\/www.muratyaman.co.uk\/blog\/index.php\/wp-json\/wp\/v2\/media?parent=563"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.muratyaman.co.uk\/blog\/index.php\/wp-json\/wp\/v2\/categories?post=563"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.muratyaman.co.uk\/blog\/index.php\/wp-json\/wp\/v2\/tags?post=563"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}