<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/php-git.git, branch php-5.6.7</title>
<subtitle>git.php.net: repository/php-src.git
</subtitle>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/php-git.git/'/>
<entry>
<title>php-5.6.7</title>
<updated>2015-03-19T00:19:30+00:00</updated>
<author>
<name>Ferenc Kovacs</name>
<email>tyrael@php.net</email>
</author>
<published>2015-03-19T00:19:30+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/php-git.git/commit/?id=effcb5a97358f01714bd833c8063a4a7abe9dff1'/>
<id>effcb5a97358f01714bd833c8063a4a7abe9dff1</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>add test for bug #68976</title>
<updated>2015-03-18T23:55:09+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2015-03-18T00:03:46+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/php-git.git/commit/?id=0197082b8eb9e7eac8b06af0e92c7e2f43e2afa6'/>
<id>0197082b8eb9e7eac8b06af0e92c7e2f43e2afa6</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Fixed bug #68976 - Use After Free Vulnerability in unserialize()</title>
<updated>2015-03-18T23:54:06+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2015-03-17T20:20:22+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/php-git.git/commit/?id=10198311a8a4f4d32988f0cce7d75b7e34f5ad38'/>
<id>10198311a8a4f4d32988f0cce7d75b7e34f5ad38</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix bug #69253 - ZIP Integer Overflow leads to writing past heap boundary</title>
<updated>2015-03-18T23:51:10+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2015-03-18T04:59:56+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/php-git.git/commit/?id=ec779124cb7279493ce1ca1088d1aaa32e82479a'/>
<id>ec779124cb7279493ce1ca1088d1aaa32e82479a</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix bug #69248 - heap overflow vulnerability in regcomp.c</title>
<updated>2015-03-18T23:42:12+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2015-03-18T00:04:57+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/php-git.git/commit/?id=5fd617f2f5afa3a687969e7844864e027f97d964'/>
<id>5fd617f2f5afa3a687969e7844864e027f97d964</id>
<content type='text'>
Merged from https://github.com/garyhouston/regex/commit/70bc2965604b6b8aaf260049e64c708dddf85334
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Merged from https://github.com/garyhouston/regex/commit/70bc2965604b6b8aaf260049e64c708dddf85334
</pre>
</div>
</content>
</entry>
<entry>
<title>Fixed bug #69134 (Per Directory Values overrides PHP_INI_SYSTEM configuration options)</title>
<updated>2015-03-18T23:41:59+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2015-03-17T20:04:36+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/php-git.git/commit/?id=7f183044fd301ed75f37983b95903b71467c29f4'/>
<id>7f183044fd301ed75f37983b95903b71467c29f4</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix bug #69207 - move_uploaded_file allows nulls in path</title>
<updated>2015-03-18T23:41:36+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2015-03-17T19:47:58+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/php-git.git/commit/?id=313ff116fa08918fb3949d51f17eb39d0b950962'/>
<id>313ff116fa08918fb3949d51f17eb39d0b950962</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix odbc build as shared</title>
<updated>2015-03-17T13:59:47+00:00</updated>
<author>
<name>Remi Collet</name>
<email>remi@php.net</email>
</author>
<published>2015-03-08T06:34:51+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/php-git.git/commit/?id=7a3fca34058b6eee258e24bd5cd647d46b6bf317'/>
<id>7a3fca34058b6eee258e24bd5cd647d46b6bf317</id>
<content type='text'>
Broken since a41aa46759d20e23af92df00b917ca66c6102412
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Broken since a41aa46759d20e23af92df00b917ca66c6102412
</pre>
</div>
</content>
</entry>
<entry>
<title>Fixed bug (#69195 Inconsistent stream crypto values across versions)</title>
<updated>2015-03-06T13:13:25+00:00</updated>
<author>
<name>Daniel Lowrey</name>
<email>rdlowrey@php.net</email>
</author>
<published>2015-03-06T03:48:47+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/php-git.git/commit/?id=95b5fb115c6b4915c4e4dc54d35d3a8be09b0ba9'/>
<id>95b5fb115c6b4915c4e4dc54d35d3a8be09b0ba9</id>
<content type='text'>
PHP 5.6.0 altered the semantics of the following constants:

- STREAM_CRYPTO_METHOD_SSLv23_CLIENT
- STREAM_CRYPTO_METHOD_SSLv23_SERVER
- STREAM_CRYPTO_METHOD_TLS_CLIENT
- STREAM_CRYPTO_METHOD_TLS_SERVER

Instead of representing the SSLv23_*() handshake methods the v23
constants were changed to allow only SSLv2 or SSLv3 connections.
Likewise, the TLS methods were modified from using only the TLSv1
handshake to allowing TLS1,1.1, and 1.2. This created a situation
in which users upgrading from previous versions faced a potential
security degradation if they did not update code to use different
constants. In the interest of compatibility across PHP versions
the original semantics have been restored with the following
caveat:

**IMPORTANT**

The SSLv23 client/server methods will no longer negotiate the use
of the insecure SSLv2 or SSLv3 protocols by default. Users wishing
to allow these protocols must explicitly add them to the method
bitmask via the appropriate flags.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
PHP 5.6.0 altered the semantics of the following constants:

- STREAM_CRYPTO_METHOD_SSLv23_CLIENT
- STREAM_CRYPTO_METHOD_SSLv23_SERVER
- STREAM_CRYPTO_METHOD_TLS_CLIENT
- STREAM_CRYPTO_METHOD_TLS_SERVER

Instead of representing the SSLv23_*() handshake methods the v23
constants were changed to allow only SSLv2 or SSLv3 connections.
Likewise, the TLS methods were modified from using only the TLSv1
handshake to allowing TLS1,1.1, and 1.2. This created a situation
in which users upgrading from previous versions faced a potential
security degradation if they did not update code to use different
constants. In the interest of compatibility across PHP versions
the original semantics have been restored with the following
caveat:

**IMPORTANT**

The SSLv23 client/server methods will no longer negotiate the use
of the insecure SSLv2 or SSLv3 protocols by default. Users wishing
to allow these protocols must explicitly add them to the method
bitmask via the appropriate flags.
</pre>
</div>
</content>
</entry>
<entry>
<title>Really fix zts this time</title>
<updated>2015-03-05T21:16:05+00:00</updated>
<author>
<name>Daniel Lowrey</name>
<email>rdlowrey@php.net</email>
</author>
<published>2015-03-05T21:08:46+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/php-git.git/commit/?id=4245c9327be61ba97ccabaefe84d6e5df3ebd1d2'/>
<id>4245c9327be61ba97ccabaefe84d6e5df3ebd1d2</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
</feed>
