1
0
mirror of https://github.com/php/php-src.git synced 2026-04-09 09:03:04 +02:00
Files
archived-php-src/sapi
Stanislav Malyshev ed709d5aa0 Merge branch 'PHP-5.5' into PHP-5.6
* PHP-5.5:
  update NEWS
  fix test
  update NEWS
  Fix bug #70019 - limit extracted files to given directory
  Do not do convert_to_* on unserialize, it messes up references
  Fix #69793 - limit what we accept when unserializing exception
  Fixed bug #70169 (Use After Free Vulnerability in unserialize() with SplDoublyLinkedList)
  Fixed bug #70166 - Use After Free Vulnerability in unserialize() with SPLArrayObject
  ignore signatures for packages too
  Fix bug #70168 - Use After Free Vulnerability in unserialize() with SplObjectStorage
  Fixed bug #69892
  Fix bug #70014 - use RAND_bytes instead of deprecated RAND_pseudo_bytes
  Improved fix for Bug #69441
  Fix bug #70068 (Dangling pointer in the unserialization of ArrayObject items)
  Fix bug #70121 (unserialize() could lead to unexpected methods execution / NULL pointer deref)
  Fix bug #70081: check types for SOAP variables

Conflicts:
	ext/soap/php_http.c
	ext/spl/spl_observer.c
2015-08-04 15:29:13 -07:00
..
2015-01-15 23:26:37 +08:00
2015-01-15 23:26:37 +08:00
2015-01-15 23:26:37 +08:00
2015-01-15 23:26:37 +08:00
2015-01-15 23:26:37 +08:00
2015-08-04 15:29:13 -07:00
2015-01-15 23:26:37 +08:00
2015-01-15 23:26:37 +08:00
2015-05-26 16:24:39 +08:00
2015-01-15 23:26:37 +08:00
2015-06-22 23:39:35 -04:00
2015-01-15 23:26:37 +08:00
2015-01-15 23:26:37 +08:00
2015-01-15 23:26:37 +08:00
2015-01-15 23:26:37 +08:00
2015-01-15 23:26:37 +08:00
2015-01-15 23:26:37 +08:00
2015-01-15 23:26:37 +08:00
2015-01-15 23:26:37 +08:00
2015-01-15 23:26:37 +08:00