RFE: PHP 5.2.12 Source Update

Bug #497826 reported by BJ Dierkes
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
IUS Community Project
Fix Released
Medium
BJ Dierkes

Bug Description

PHP 5.2.12 Released!
[17-Dec-2009]

The PHP development team would like to announce the immediate availability of PHP 5.2.12. This release focuses on improving the stability of the PHP 5.2.x branch with over 60 bug fixes, some of which are security related. All users of PHP 5.2 are encouraged to upgrade to this release.

Security Enhancements and Fixes in PHP 5.2.12:

    * Fixed a safe_mode bypass in tempnam() identified by Grzegorz Stachowiak. (CVE-2009-3557, Rasmus)
    * Fixed a open_basedir bypass in posix_mkfifo() identified by Grzegorz Stachowiak. (CVE-2009-3558, Rasmus)
    * Added "max_file_uploads" INI directive, which can be set to limit the number of file uploads per-request to 20 by default, to prevent possible DOS via temporary file exhaustion, identified by Bogdan Calin. (CVE-2009-4017, Ilia)
    * Added protection for $_SESSION from interrupt corruption and improved "session.save_path" check, identified by Stefan Esser. (CVE-2009-4143, Stas)
    * Fixed bug #49785 (insufficient input string validation of htmlspecialchars()). (CVE-2009-4142, Moriyoshi, hello at iwamot dot com)

Further details about the PHP 5.2.12 release can be found in the release announcement, and the full list of changes are available in the ChangeLog.

BJ Dierkes (derks)
Changed in ius:
assignee: nobody → BJ Dierkes (derks)
milestone: none → php52-5.2.12-1
Revision history for this message
BJ Dierkes (derks) wrote :

Also rebuild the following:

php52-pecl-memcache
php52-pecl-apc

Revision history for this message
BJ Dierkes (derks) wrote :

Pushed all packages to ius-el5-testing (and just php52 to ius-el4-testing).

tags: added: testing
Revision history for this message
BJ Dierkes (derks) wrote :

This has been pushed to ius-el5 stable and ius-el4 (just php52).

Changed in ius:
status: In Progress → Fix Released
tags: removed: php52 testing
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.