2007年11月10日 星期六

PHP 5.2.5 Released

剛剛PHP開放團隊放出PHP5.2.5版
本次釋放版本主要改進於PHP5.2系列的
穩定性及超過60個bug的修正其中包含數個
安全性相關的問題
主要修正列表
Fixed dl() to only accept filenames. Reported by Laurent Gaffie.
Fixed dl() to limit argument size to MAXPATHLEN (CVE-2007-4887). Reported by Laurent Gaffie.
Fixed htmlentities/htmlspecialchars not to accept partial multibyte sequences. Reported by Rasmus Lerdorf
Fixed possible triggering of buffer overflows inside glibc implementations of the fnmatch(), setlocale() and glob() functions. Reported by Laurent Gaffie.
Fixed "mail.force_extra_parameters" php.ini directive not to be modifiable in .htaccess due to the security implications. Reported by SecurityReason.
Fixed bug #42869 (automatic session id insertion adds sessions id to non-local forms).
Fixed bug #41561 (Values set with php_admin_* in httpd.conf can be overwritten with ini_set())

下載
http://www.php.net/downloads.php#v5

沒有留言: