diff --git a/NEWS b/NEWS index 4905156bc5a..e54e83aa20b 100644 --- a/NEWS +++ b/NEWS @@ -186,6 +186,8 @@ PHP NEWS - Phar: . Fixed bug #71354 (Heap corruption in tar/zip/phar parser). (Stas) + . Fixed bug #71331 (Uninitialized pointer in phar_make_dirstream()). + (CVE-2016-4343) (Stas) . Fixed bug #71391 (NULL Pointer Dereference in phar_tar_setupmetadata()). (Stas) . Fixed bug #71488 (Stack overflow when decompressing tar archives). (Stas)