PHP is een zogenoemde hypertext preprocessor en wordt voornamelijk toegepast om dynamische content in de opmaaktaal html serverside te genereren. De software wordt veelal gebruikt in combinatie met het databaseprogramma Mysql, waarmee de dynamische content van websites en forums worden geserveerd. De ontwikkelaars van The PHP Group hebben versie 5.2.7 vrijgegeven en voorzien van de volgende aankondiging:
The PHP development team would like to announce the immediateavailability of PHP 5.2.7. This release focuses on improving the stability ofthe PHP 5.2.x branch with over 120 bug fixes, several of which are security related. All users of PHP are encouraged to upgrade to this release.
Security Enhancements and Fixes in PHP 5.2.7:Key enhancements in PHP 5.2.7 include:
- Upgraded PCRE to version 7.8 (Fixes CVE-2008-2371)
- Fixed missing initialization of BG(page_uid) and BG(page_gid), reported by Maksymilian Arciemowicz.
- Fixed incorrect php_value order for Apache configuration, reported by Maksymilian Arciemowicz.
- Fixed a crash inside gd with invalid fonts (Fixes CVE-2008-3658).
- Fixed a possible overflow inside memnstr (Fixes CVE-2008-3659).
- Fixed security issues detailed in CVE-2008-2665 and CVE-2008-2666.
- Fixed bug #45151 (Crash with URI/file..php (filename contains 2 dots)).(Fixes CVE-2008-3660)
- Fixed bug #42862 (IMAP toolkit crash: rfc822.c legacy routine buffer overflow). (Fixes CVE-2008-2829)
For users upgrading from PHP 5.0 and PHP 5.1, an upgrade guide is available here, detailing the changes between those releases and PHP 5.2.7. For a full list of changes in PHP 5.2.7, see the ChangeLog.
- Fixed several memory leaks inside the readline and sqlite extensions
- A number of corrections relating to date parsing inside the date extension
- Fixed bugs relating to data retrieval in the PDO extension
- A series of crashes in various areas of code were resolved
- Several corrections were made to the strip_tags() function in terms of < and <?XML handling
- A number of bugs were fixed in extract() function when EXTR_REFS flag is being used
- Added the ability to log PHP errors to the SAPI (Ex. Apache log) logging facility
- Over 170 bug fixes.