Stanislav Malyshev
8d3dfabef4
Fix #77369 - memcpy with negative length via crafted DNS response
2019-01-06 11:39:09 -08:00
Stanislav Malyshev
31f59e1f30
Fix more issues with encodilng length
...
Should fix bug #77381 , bug #77382 , bug #77385 , bug #77394 .
2019-01-06 11:38:46 -08:00
Christoph M. Becker
567c9f5842
Fix #77270 : imagecolormatch Out Of Bounds Write on Heap
...
At least some of the image reading functions may return images which
use color indexes greater than or equal to im->colorsTotal. We cater
to this by always using a buffer size which is sufficient for
`gdMaxColors` in `gdImageColorMatch()`.
2019-01-06 11:38:46 -08:00
Stanislav Malyshev
4feb9e66ff
Fix bug #77380 (Global out of bounds read in xmlrpc base64 code)
2019-01-06 11:38:46 -08:00
Stanislav Malyshev
c6e34d91b8
Fix bug #77371 (heap buffer overflow in mb regex functions - compile_string_node)
2019-01-06 11:38:46 -08:00
Stanislav Malyshev
deb06bbb9c
Fix bug #77370 - check that we do not read past buffer end when parsing multibytes
2019-01-06 11:38:46 -08:00
Christoph M. Becker
dfd8237aec
Fix #77269 : Potential unsigned underflow in gdImageScale
...
Belatedly, we're porting the respective upstream patch[1].
[1] <60bfb401ad >
2019-01-06 11:38:46 -08:00
Stanislav Malyshev
78bd347774
Fix bug #77247 (heap buffer overflow in phar_detect_phar_fname_ext)
2019-01-06 11:38:46 -08:00
Stanislav Malyshev
9c62b95e5e
Fix bug #77242 (heap out of bounds read in xmlrpc_decode())
2019-01-06 11:38:46 -08:00
Alexander Kurilo
e3e3289bd1
Regenerate certs for openssl tests
2019-01-06 11:38:46 -08:00
Stanislav Malyshev
d5dc3c69f9
Merge branch 'PHP-7.0' into PHP-7.1
...
* PHP-7.0:
Fix null pointer deref in qprint-encode filter (bug #77231 )
2018-12-03 10:19:57 -08:00
Stanislav Malyshev
036bc5c1fb
Merge branch 'PHP-5.6' into PHP-7.0
...
* PHP-5.6:
Fix null pointer deref in qprint-encode filter (bug #77231 )
2018-12-03 10:19:49 -08:00
Stanislav Malyshev
78bffa72c1
Fix null pointer deref in qprint-encode filter (bug #77231 )
2018-12-03 10:19:08 -08:00
Stanislav Malyshev
8ab5d22332
Merge branch 'PHP-7.0' into PHP-7.1
...
* PHP-7.0:
Fix bug #77143 - add more checks to buffer reads
Fix bug #77143 - add more checks to buffer reads
Fix #77020 : null pointer dereference in imap_mail
2018-12-03 00:42:45 -08:00
Stanislav Malyshev
5718d73dbb
Merge branch 'PHP-5.6' into PHP-7.0
...
* PHP-5.6:
Fix bug #77143 - add more checks to buffer reads
2018-12-03 00:42:35 -08:00
Stanislav Malyshev
48f0f73f75
Fix bug #77143 - add more checks to buffer reads
2018-12-03 00:41:46 -08:00
Stanislav Malyshev
66a0f061f6
Merge branch 'PHP-5.6' into PHP-7.0
...
* PHP-5.6:
Fix bug #77143 - add more checks to buffer reads
Fix #77020 : null pointer dereference in imap_mail
2018-12-03 00:39:03 -08:00
Stanislav Malyshev
54212674b9
Fix bug #77143 - add more checks to buffer reads
2018-12-03 00:03:10 -08:00
Stanislav Malyshev
7edc639b9f
Fix #77020 : null pointer dereference in imap_mail
...
If an empty $message is passed to imap_mail(), we must not set message
to NULL, since _php_imap_mail() is not supposed to handle NULL pointers
(opposed to pointers to NUL).
2018-12-03 00:00:56 -08:00
Stanislav Malyshev
f8eac1f438
Merge branch 'PHP-7.0' into PHP-7.1
...
* PHP-7.0:
Fix TSRM signature - php_stream_stat macro has it's own TSRM
Regenerate certificates for openssl tests
Improve test for bug77022
2018-12-02 13:38:59 -08:00
Stanislav Malyshev
6e3f5d57d4
Merge branch 'PHP-5.6' into PHP-7.0
...
* PHP-5.6:
Fix TSRM signature - php_stream_stat macro has it's own TSRM
Regenerate certificates for openssl tests
Improve test for bug77022
2018-12-02 13:18:07 -08:00
Stanislav Malyshev
aabdb71dc3
Fix TSRM signature - php_stream_stat macro has it's own TSRM
2018-12-02 12:54:19 -08:00
Alexander Kurilo
0382e761d7
Regenerate certificates for openssl tests
2018-12-02 12:08:19 -08:00
Stanislav Malyshev
2fba1e2f59
Improve test for bug77022
2018-12-02 12:06:13 -08:00
Stanislav Malyshev
09885f78c6
Merge branch 'PHP-7.0' into PHP-7.1
...
* PHP-7.0:
2018-12-01 21:48:35 -08:00
Stanislav Malyshev
cea277048d
Merge branch 'PHP-5.6' into PHP-7.0
...
* PHP-5.6:
Fix bug #77022 - use file mode or umask for new files
2018-12-01 21:48:27 -08:00
Stanislav Malyshev
1aec05defd
Merge branch 'PHP-7.0' into PHP-7.1
...
* PHP-7.0:
Fix bug #77022 - use file mode or umask for new files
2018-12-01 21:47:37 -08:00
Stanislav Malyshev
67f3615102
Merge branch 'PHP-5.6' into PHP-7.0
...
* PHP-5.6:
Fix bug #77022 - use file mode or umask for new files
2018-12-01 21:08:38 -08:00
Stanislav Malyshev
69f5e7992b
Fix bug #77022 - use file mode or umask for new files
2018-12-01 21:06:45 -08:00
Stanislav Malyshev
223b8c15a8
Merge branch 'PHP-7.0' into PHP-7.1
...
* PHP-7.0:
Add DISPLAY_INI_ENTRIES for imap
Disable rsh/ssh functionality in imap by default (bug #77153 )
Disable rsh/ssh functionality in imap by default (bug #77153 )
2018-11-28 15:46:53 -08:00
Stanislav Malyshev
87bf84c8c7
Merge branch 'PHP-5.6' into PHP-7.0
...
* PHP-5.6:
Add DISPLAY_INI_ENTRIES for imap
2018-11-28 15:46:39 -08:00
Stanislav Malyshev
d8765852e0
Add DISPLAY_INI_ENTRIES for imap
2018-11-28 15:45:51 -08:00
Stanislav Malyshev
05782f01f5
Disable rsh/ssh functionality in imap by default (bug #77153 )
2018-11-20 11:16:08 -08:00
Stanislav Malyshev
628df47e79
Disable rsh/ssh functionality in imap by default (bug #77153 )
2018-11-20 11:14:07 -08:00
Remi Collet
d9afc2f662
Fix #77151 ftp_close(): SSL_read on shutdown
...
Regression introduced in fix for #76972
only display the error message when sslerror
or if errno is set (for SSL_ERROR_SYSCALL case)
2018-11-20 11:18:34 +01:00
Stanislav Malyshev
e5bfea64c8
Disable rsh/ssh functionality in imap by default (bug #77153 )
2018-11-20 00:13:50 -08:00
Anatol Belski
0434141ce9
Fixed bug #77047 pg_convert has a broken regex for the 'TIME WITHOUT TIMEZONE' data type
...
Backport 369c991d and 282a63da to 7.1, closes #3634
2018-11-18 12:29:34 +01:00
Christoph M. Becker
a56cdd0a82
Fix #77147 : Fix for 60494 ignores ICONV_MIME_DECODE_CONTINUE_ON_ERROR
...
If the `ICONV_MIME_DECODE_CONTINUE_ON_ERROR` flag is set, parsing
should not fail, if there are illegal characters in the headers;
instead we silently ignore these like before.
2018-11-14 14:55:38 +01:00
Thiago Carvalho
ec2e7a2d48
Validate length on socket_write
2018-11-13 12:56:37 +01:00
Christoph M. Becker
f6079e3c56
Fix #77141 : Signedness issue in SOAP when precision=-1
...
According to php_gcvt(), we assume at most 17 fractional digits for
negative precision.
2018-11-12 23:19:30 +01:00
Christoph M. Becker
625f614cb1
Fix #76348 : WSDL_CACHE_MEMORY causes Segmentation fault
...
“Thou shalt not follow the NULL pointer, for chaos and madness await
thee at its end.”
2018-11-04 16:40:27 +01:00
Derick Rethans
e58388ea6d
Updated to version 2018.7 (2018g)
2018-10-30 11:25:45 +00:00
Jon Allen
8775bead3a
fix bug #77079
2018-10-30 00:19:07 +01:00
Nikita Popov
f1ceec5533
Fixed bug #77058
...
Account for the fact that undef must be interpreted as null for
the purposes of INC/DEC inference.
2018-10-25 16:37:41 +02:00
Nikita Popov
e7153e8a2f
Improve "narrowing" error message
...
By including the opcode name.
2018-10-25 16:36:23 +02:00
Derick Rethans
41241d109a
Updated to version 2018.6 (2018f)
2018-10-22 12:05:39 +01:00
Anatol Belski
4461fb9c26
Fix tests for ICU 63.1
...
The most of change is U+00A0 vs. new U+202F used in some outputs.
2018-10-20 23:02:06 +02:00
Peter Kokot
447b41f6bb
Fix #77035 : The phpize and ./configure create redundant .deps file
...
The `.deps` file(s) was once used by Automake and created to write
dependencies to it. The file creation has been removed via the commit
779c11af21 .
The phpize and ./configure script create a redundant .deps file in a
PECL extension directory which might cause confusions why is it used.
Today it is no longer relevant so this redundant artefact can be
removed in the phpize configure script.
2018-10-19 00:02:09 +02:00
Anatol Belski
fda06127fa
Fix test when it's run on another drive
2018-10-18 00:43:24 +02:00
Christoph M. Becker
8a9e0312ce
Fix #77027 : tidy::getOptDoc() not available on Windows
...
We define the `HAVE_TIDYOPTGETDOC` macro unconditionally, since the
Windows PHP SDK ships libtidy 2009/04/06 or newer for a long time.
We do not add a regression test, since 021.phpt already tests
`tidy_get_opt_doc`, but has previously been skipped due to
unavailability of the function.
2018-10-17 16:27:07 +02:00