summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
* Set versionsphp-7.0.30PHP-7.0.30Anatol Belski2018-04-243-4/+4
|
* [ci skip] Update NEWSAnatol Belski2018-04-241-0/+12
|
* Merge branch 'PHP-5.6' into PHP-7.0Anatol Belski2018-04-241-2/+4
|\ | | | | | | | | * PHP-5.6: Fix test portability
| * Fix test portabilityAnatol Belski2018-04-241-2/+4
| |
* | Merge branch 'PHP-5.6' into PHP-7.0Stanislav Malyshev2018-04-2321-18/+101
|\ \ | |/ | | | | | | | | | | | | | | | | | | * PHP-5.6: Fix tsrm_ls Fix #76129 - remove more potential unfiltered outputs for phar Fix test Fix bug #76248 - Malicious LDAP-Server Response causes Crash Fix bug #76249 - fail on invalid sequences Fix #76130: Heap Buffer Overflow (READ: 1786) in exif_iif_add_value Fix bug #75981: prevent reading beyond buffer start
| * Fix tsrm_lsStanislav Malyshev2018-04-231-1/+1
| |
| * Merge remote-tracking branch 'security/bug76249' into PHP-5.6Stanislav Malyshev2018-04-232-0/+21
| |\ | | | | | | | | | | | | | | | * security/bug76249: Fix test Fix bug #76249 - fail on invalid sequences
| | * Fix testStanislav Malyshev2018-04-221-2/+4
| | |
| | * Fix bug #76249 - fail on invalid sequencesStanislav Malyshev2018-04-222-0/+19
| | |
| * | Merge remote-tracking branch 'security/bug76248' into PHP-5.6Stanislav Malyshev2018-04-232-1/+45
| |\ \ | | | | | | | | | | | | | | | | * security/bug76248: Fix bug #76248 - Malicious LDAP-Server Response causes Crash
| | * | Fix bug #76248 - Malicious LDAP-Server Response causes CrashStanislav Malyshev2018-04-222-1/+45
| | |/
| * | Fix #76129 - remove more potential unfiltered outputs for pharStanislav Malyshev2018-04-2313-16/+14
| | |
| * | Merge remote-tracking branch 'security/PHP-5.6' into PHP-5.6Stanislav Malyshev2018-04-234-1/+21
| |\ \ | | |/ | |/| | | | | | | | | | * security/PHP-5.6: Fix #76130: Heap Buffer Overflow (READ: 1786) in exif_iif_add_value Fix bug #75981: prevent reading beyond buffer start
| | * Fix #76130: Heap Buffer Overflow (READ: 1786) in exif_iif_add_valueChristoph M. Becker2018-04-224-1/+21
| | | | | | | | | | | | | | | | | | The MakerNote is not necessarily null-terminated, so we must not use `strlen()` to avoid OOB reads. Instead `php_strnlen()` is the proper way to handle this.
| | * Fix bug #75981: prevent reading beyond buffer startStanislav Malyshev2018-02-202-2/+34
| | |
* | | Merge branch 'PHP-5.6' into PHP-7.0Ferenc Kovacs2018-03-280-0/+0
|\ \ \ | |/ /
| * | [ci skip] 5.6.36 will be nextFerenc Kovacs2018-03-283-5/+7
| | |
* | | [ci skip] Fix release dateAnatol Belski2018-03-271-1/+1
| | |
* | | 7.0.30 nextAnatol Belski2018-03-273-5/+9
| | |
* | | [ci skip] Update NEWSAnatol Belski2018-03-271-1/+3
| | |
* | | Merge branch 'PHP-5.6' into PHP-7.0Anatol Belski2018-03-270-0/+0
|\ \ \ | |/ / | | | | | | | | | * PHP-5.6: [ci skip] Update NEWS
| * | [ci skip] Update NEWSAnatol Belski2018-03-271-0/+4
| | |
* | | Do not set PR_SET_DUMPABLE by defaultJakub Zelenka2018-03-274-1/+11
| | |
* | | Merge branch 'PHP-5.6' into PHP-7.0Anatol Belski2018-03-270-0/+0
|\ \ \ | |/ / | | | | | | | | | * PHP-5.6: Do not set PR_SET_DUMPABLE by default
| * | Do not set PR_SET_DUMPABLE by defaultJakub Zelenka2018-03-274-1/+11
| | |
* | | Merge branch 'PHP-5.6' into PHP-7.0Ferenc Kovacs2018-02-280-0/+0
|\ \ \ | |/ /
| * | 5.6.35 is nextFerenc Kovacs2018-02-273-5/+7
| | |
* | | 7.0.29 nextAnatol Belski2018-02-273-5/+9
| | |
* | | [ci skip] Update NEWSAnatol Belski2018-02-271-0/+3
| | |
* | | Merge branch 'PHP-5.6' into PHP-7.0Anatol Belski2018-02-270-0/+0
|\ \ \ | |/ / | | | | | | | | | * PHP-5.6: [ci skip] Update NEWS
| * | [ci skip] Update NEWSAnatol Belski2018-02-271-0/+3
| | |
* | | Merge branch 'PHP-5.6' into PHP-7.0Stanislav Malyshev2018-02-262-2/+34
|\ \ \ | |/ / | | | | | | | | | * PHP-5.6: Fix bug #75981: prevent reading beyond buffer start
| * | Fix bug #75981: prevent reading beyond buffer startStanislav Malyshev2018-02-262-2/+34
| | |
* | | Merge branch 'PHP-5.6' into PHP-7.0Stanislav Malyshev2018-02-231-1/+1
|\ \ \ | |/ / | | | | | | | | | * PHP-5.6: [ci skip] Set FPM maintainership
| * | [ci skip] Set FPM maintainershipStanislav Malyshev2018-02-231-1/+1
| |/ | | | | | | | | As per http://news.php.net/php.internals/101897, Jakub is officially annointed as new FPM maintainer.
* | Use Z_EXPECTED_LONG to initialize FAST_ZPP parsing loopSara Golemon2018-01-231-1/+1
| |
* | Merge branch 'PHP-5.6' into PHP-7.0Remi Collet2018-01-030-0/+0
|\ \ | |/ | | | | | | * PHP-5.6: 2018
| * 2018Remi Collet2018-01-031-2/+2
| |
* | 2018Remi Collet2018-01-031-2/+2
| |
* | Merge branch 'PHP-5.6' into PHP-7.0Ferenc Kovacs2018-01-030-0/+0
|\ \ | |/
| * php 5.6.34 is nextFerenc Kovacs2018-01-033-5/+7
| |
* | [ci skip] update NEWSAnatol Belski2018-01-021-0/+6
| |
* | Merge branch 'PHP-5.6' into PHP-7.0Stanislav Malyshev2018-01-0117-50/+65
|\ \ | |/ | | | | | | | | | | * PHP-5.6: Update NEWS Fixed bug #75571: Potential infinite loop in gdImageCreateFromGifCtx Fix bug #74782: remove file name from output to avoid XSS
| * Update NEWSStanislav Malyshev2018-01-011-1/+7
| |
| * Fixed bug #75571: Potential infinite loop in gdImageCreateFromGifCtxChristoph M. Becker2018-01-013-5/+20
| | | | | | | | | | | | | | Due to a signedness confusion in `GetCode_` a corrupt GIF file can trigger an infinite loop. Furthermore we make sure that a GIF without any palette entries is treated as invalid *after* open palette entries have been removed.
| * Fix bug #74782: remove file name from output to avoid XSSStanislav Malyshev2018-01-0114-45/+45
| |
* | [ci skip] update NEWSAnatol Belski2017-12-221-4/+4
| |
* | Fixed bug #75579 (Interned strings buffer overflow may cause crash)Dmitry Stogov2017-12-222-3/+33
| | | | | | | | (cherry picked from commit 37bf8bdc1494abb2ce5cac40e0be80e23682f851)
* | 7.0.28 is nextAnatol Belski2017-12-053-5/+9
| |
* | [ci skip] update NEWSAnatol Belski2017-12-051-0/+1
| |