PHP NEWS ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||| 19 Dec 2019, PHP 7.4.1 - Bcmath: . Fixed bug #78878 (Buffer underflow in bc_shift_addsub). (CVE-2019-11046). (cmb) - Core: . Fixed bug #78862 (link() silently truncates after a null byte on Windows). (CVE-2019-11044). (cmb) . Fixed bug #78863 (DirectoryIterator class silently truncates after a null byte). (CVE-2019-11045). (cmb) . Fixed bug #78943 (mail() may release string with refcount==1 twice). (CVE-2019-11049). (cmb) . Fixed bug #78810 (RW fetches do not throw "uninitialized property" exception). (Nikita) . Fixed bug #78868 (Calling __autoload() with incorrect EG(fake_scope) value). (Antony Dovgal, Dmitry) . Fixed bug #78296 (is_file fails to detect file). (cmb) . Fixed bug #78883 (fgets(STDIN) fails on Windows). (cmb) . Fixed bug #78898 (call_user_func(['parent', ...]) fails while other succeed). (Nikita) . Fixed bug #78904 (Uninitialized property triggers __get()). (Nikita) . Fixed bug #78926 (Segmentation fault on Symfony cache:clear). (Nikita) - GD: . Fixed bug #78849 (GD build broken with -D SIGNED_COMPARE_SLOW). (cmb) . Fixed bug #78923 (Artifacts when convoluting image with transparency). (wilson chen) - EXIF: . Fixed bug #78793 (Use-after-free in exif parsing under memory sanitizer). (CVE-2019-11050). (Nikita) . Fixed bug #78910 (Heap-buffer-overflow READ in exif). (CVE-2019-11047). (Nikita) - FPM: . Fixed bug #76601 (Partially working php-fpm ater incomplete reload). (Maksim Nikulin) . Fixed bug #78889 (php-fpm service fails to start). (Jakub Zelenka) . Fixed bug #78916 (php-fpm 7.4.0 don't send mail via mail()). (Jakub Zelenka) - Intl: . Implemented FR #78912 (INTL Support for accounting format). (cmb) - Mysqlnd: . Fixed bug #78823 (ZLIB_LIBS not added to EXTRA_LIBS). (Arjen de Korte) - OPcache: . Fixed $x = (bool)$x; with opcache (should emit undeclared variable notice). (Tyson Andre) . Fixed bug #78935 (Preloading removes classes that have dependencies). (Nikita, Dmitry) - PCRE: . Fixed bug #78853 (preg_match() may return integer > 1). (cmb) - Reflection: . Fixed bug #78895 (Reflection detects abstract non-static class as abstract static. IS_IMPLICIT_ABSTRACT is not longer used). (Dmitry) - Standard: . Fixed bug #77638 (var_export'ing certain class instances segfaults). (cmb) . Fixed bug #78840 (imploding $GLOBALS crashes). (cmb) . Fixed bug #78833 (Integer overflow in pack causes out-of-bound access). (cmb) . Fixed bug #78814 (strip_tags allows / in tag name => whitelist bypass). (cmb) 28 Nov 2019, PHP 7.4.0 - Core: . Implemented RFC: Deprecate curly brace syntax for accessing array elements and string offsets. https://wiki.php.net/rfc/deprecate_curly_braces_array_access (Andrey Gromov) . Implemented RFC: Deprecations for PHP 7.4. https://wiki.php.net/rfc/deprecations_php_7_4 (Kalle, Nikita) . Fixed bug #52752 (Crash when lexing). (Nikita) . Fixed bug #60677 (CGI doesn't properly validate shebang line contains #!). (Nikita) . Fixed bug #71030 (Self-assignment in list() may have inconsistent behavior). (Nikita) . Fixed bug #72530 (Use After Free in GC with Certain Destructors). (Nikita) . Fixed bug #75921 (Inconsistent: No warning in some cases when stdObj is created on the fly). (David Walker) . Implemented FR #76148 (Add array_key_exists() to the list of specially compiled functions). (Majkl578) . Fixed bug #76430 (__METHOD__ inconsistent outside of method). (Ryan McCullagh, Nikita) . Fixed bug #76451 (Aliases during inheritance type checks affected by opcache). (Nikita) . Implemented FR #77230 (Support custom CFLAGS and LDFLAGS from environment). (cmb) . Fixed bug #77345 (Stack Overflow caused by circular reference in garbage collection). (Alexandru Patranescu, Nikita, Dmitry) . Fixed bug #77812 (Interactive mode does not support PHP 7.3-style heredoc). (cmb, Nikita) . Fixed bug #77877 (call_user_func() passes $this to static methods). (Dmitry) . Fixed bug #78066 (PHP eats the first byte of a program that comes from process substitution). (Nikita) . Fixed bug #78151 (Segfault caused by indirect expressions in PHP 7.4a1). (Nikita) . Fixed bug #78154 (SEND_VAR_NO_REF does not always send reference). (Nikita) . Fixed bug #78182 (Segmentation fault during by-reference property assignment). (Nikita) . Fixed bug #78212 (Segfault in built-in webserver). (cmb) . Fixed bug #78220 (Can't access OneDrive folder). (cmb, ab) . Fixed bug #78226 (Unexpected __set behavior with typed properties). (Nikita) . Fixed bug #78239 (Deprecation notice during string conversion converted to exception hangs). (Nikita) . Fixed bug #78335 (Static properties/variables containing cycles report as leak). (Nikita) . Fixed bug #78340 (Include of stream wrapper not reading whole file). (Nikita) . Fixed bug #78344 (Segmentation fault on zend_check_protected). (Nikita) . Fixed bug #78356 (Array returned from ArrayAccess is incorrectly unpacked as argument). (Nikita) . Fixed bug #78379 (Cast to object confuses GC, causes crash). (Dmitry) . Fixed bug #78386 (fstat mode has unexpected value on PHP 7.4). (cmb) . Fixed bug #78396 (Second file_put_contents in Shutdown hangs script). (Nikita) . Fixed bug #78406 (Broken file includes with user-defined stream filters). (Nikita) . Fixed bug #78438 (Corruption when __unserializing deeply nested structures). (cmb, Nikita) . Fixed bug #78441 (Parse error due to heredoc identifier followed by digit). (cmb) . Fixed bug #78454 (Consecutive numeric separators cause OOM error). (Theodore Brown) . Fixed bug #78460 (PEAR installation failure). (Peter Kokot, L. Declercq) . Fixed bug #78531 (Crash when using undefined variable as object). (Dmitry) . Fixed bug #78535 (auto_detect_line_endings value not parsed as bool). (bugreportuser) . Fixed bug #78604 (token_get_all() does not properly tokenize FOOstat modifies $dbc->affected_rows). (Derick) . Fixed bug #76809 (SSL settings aren't respected when persistent connections are used). (fabiomsouto) . Fixed bug #78179 (MariaDB server version incorrectly detected). (cmb) . Fixed bug #78213 (Empty row pocket). (cmb) - MySQLnd: . Fixed connect_attr issues and added the _server_host connection attribute. (Qianqian Bu) . Fixed bug #60594 (mysqlnd exposes 160 lines of stats in phpinfo). (PeeHaa) - ODBC: . Fixed bug #78473 (odbc_close() closes arbitrary resources). (cmb) - Opcache: . Implemented preloading RFC: https://wiki.php.net/rfc/preload. (Dmitry) . Add opcache.preload_user INI directive. (Dmitry) . Added new INI directive opcache.cache_id (Windows only). (cmb) . Fixed bug #78106 (Path resolution fails if opcache disabled during request). (Nikita) . Fixed bug #78175 (Preloading segfaults at preload time and at runtime). (Dmitry) . Fixed bug #78202 (Opcache stats for cache hits are capped at 32bit NUM). (cmb) . Fixed bug #78271 (Invalid result of if-else). (Nikita) . Fixed bug #78341 (Failure to detect smart branch in DFA pass). (Nikita) . Fixed bug #78376 (Incorrect preloading of constant static properties). (Dmitry) . Fixed bug #78429 (opcache_compile_file(__FILE__); segfaults). (cmb) . Fixed bug #78512 (Cannot make preload work). (Dmitry) . Fixed bug #78514 (Preloading segfaults with inherited typed property). (Nikita) . Fixed bug #78654 (Incorrectly computed opcache checksum on files with non-ascii characters). (mhagstrand) - OpenSSL: . Added TLS 1.3 support to streams including new tlsv1.3 stream. (Codarren Velvindron, Jakub Zelenka) . Added openssl_x509_verify function. (Ben Scholzen) . openssl_random_pseudo_bytes() now throws in error conditions. (Sammy Kaye Powers) . Changed the default config path (Windows only). (cmb) . Fixed bug #78231 (Segmentation fault upon stream_socket_accept of exported socket-to-stream). (Nikita) . Fixed bug #78391 (Assertion failure in openssl_random_pseudo_bytes). (Nikita) . Fixed bug #78775 (TLS issues from HTTP request affecting other encrypted connections). (Nikita) - Pcntl: . Fixed bug #77335 (PHP is preventing SIGALRM from specifying SA_RESTART). (Nikita) - PCRE: . Implemented FR #77094 (Support flags in preg_replace_callback). (Nikita) . Fixed bug #72685 (Repeated UTF-8 validation of same string in UTF-8 mode). (Nikita) . Fixed bug #73948 (Preg_match_all should return NULLs on trailing optional capture groups). . Fixed bug #78338 (Array cross-border reading in PCRE). (cmb) . Fixed bug #78349 (Bundled pcre2 library missing LICENCE file). (Peter Kokot) - PDO: . Implemented FR #71885 (Allow escaping question mark placeholders). https://wiki.php.net/rfc/pdo_escape_placeholders (Matteo) . Fixed bug #77849 (Disable cloning of PDO handle/connection objects). (camporter) . Implemented FR #78033 (PDO - support username & password specified in DSN). (sjon) - PDO_Firebird: . Implemented FR #65690 (PDO_Firebird should also support dialect 1). (Simonov Denis) . Implemented FR #77863 (PDO firebird support type Boolean in input parameters). (Simonov Denis) - PDO_MySQL: . Fixed bug #41997 (SP call yields additional empty result set). (cmb) . Fixed bug #78623 (Regression caused by "SP call yields additional empty result set"). (cmb) - PDO_OCI: . Support Oracle Database tracing attributes ACTION, MODULE, CLIENT_INFO, and CLIENT_IDENTIFIER. (Cameron Porter) . Implemented FR #76908 (PDO_OCI getColumnMeta() not implemented). (Valentin Collet, Chris Jones, Remi) - PDO_SQLite: . Implemented sqlite_stmt_readonly in PDO_SQLite. (BohwaZ) . Raised requirements to SQLite 3.5.0. (cmb) . Fixed bug #78192 (SegFault when reuse statement after schema has changed). (Vincent Quatrevieux) . Fixed bug #78348 (Remove -lrt from pdo_sqlite.so). (Peter Kokot) - Phar: . Fixed bug #77919 (Potential UAF in Phar RSHUTDOWN). (cmb) - phpdbg: . Fixed bug #76596 (phpdbg support for display_errors=stderr). (kabel) . Fixed bug #76801 (too many open files). (alekitto) . Fixed bug #77800 (phpdbg segfaults on listing some conditional breakpoints). (krakjoe) . Fixed bug #77805 (phpdbg build fails when readline is shared). (krakjoe) - Recode: . Unbundled the recode extension. (cmb) - Reflection: . Fixed bug #76737 (Unserialized reflection objects are broken, they shouldn't be serializable). (Nikita) . Fixed bug #78263 (\ReflectionReference::fromArrayElement() returns null while item is a reference). (Nikita) . Fixed bug #78410 (Cannot "manually" unserialize class that is final and extends an internal one). (Nikita) . Fixed bug #78697 (ReflectionClass::implementsInterface - inaccurate error message with traits). (villfa) . Fixed bug #78774 (ReflectionNamedType on Typed Properties Crash). (Nikita) - Session: . Fixed bug #78624 (session_gc return value for user defined session handlers). (bshaffer) - SimpleXML: . Implemented FR #65215 (SimpleXMLElement could register as implementing Countable). (LeSuisse) . Fixed bug #75245 (Don't set content of elements with only whitespaces). (eriklundin) - Sockets: . Fixed bug #67619 (Validate length on socket_write). (thiagooak) . Fixed bug #78665 (Multicasting may leak memory). (cmb) - sodium: . Fixed bug #77646 (sign_detached() strings not terminated). (Frank) . Fixed bug #78510 (Partially uninitialized buffer returned by sodium_crypto_generichash_init()). (Frank Denis, cmb) . Fixed bug #78516 (password_hash(): Memory cost is not in allowed range). (cmb, Nikita) - SPL: . Fixed bug #77518 (SeekableIterator::seek() should accept 'int' typehint as documented). (Nikita) . Fixed bug #78409 (Segfault when creating instance of ArrayIterator without constructor). (Nikita) . Fixed bug #78436 (Missing addref in SplPriorityQueue EXTR_BOTH mode). (Nikita) . Fixed bug #78456 (Segfault when serializing SplDoublyLinkedList). (Nikita) - SQLite3: . Unbundled libsqlite. (cmb) . Raised requirements to SQLite 3.7.4. (cmb) . Forbid (un)serialization of SQLite3, SQLite3Stmt and SQLite3Result. (cmb) . Added support for the SQLite @name notation. (cmb, BohwaZ) . Added SQLite3Stmt::getSQL() to retrieve the SQL of the statement. (Bohwaz) . Implement FR ##70950 (Make SQLite3 Online Backup API available). (BohwaZ) - Standard: . Implemented password hashing registry RFC: https://wiki.php.net/rfc/password_registry. (Sara) . Implemented RFC where password_hash() has argon2i(d) implementations from ext/sodium when PHP is built without libargon: https://wiki.php.net/rfc/sodium.argon.hash (Sara) . Implemented FR #38301 (field enclosure behavior in fputcsv). (cmb) . Implemented FR #51496 (fgetcsv should take empty string as an escape). (cmb) . Fixed bug #73535 (php_sockop_write() returns 0 on error, can be used to trigger Denial of Service). (Nikita) . Fixed bug #74764 (Bindto IPv6 works with file_get_contents but fails with stream_socket_client). (Ville Hukkamäki) . Fixed bug #76859 (stream_get_line skips data if used with data-generating filter). (kkopachev) . Implemented FR #77377 (No way to handle CTRL+C in Windows). (Anatol) . Fixed bug #77930 (stream_copy_to_stream should use mmap more often). (Nikita) . Implemented FR #78177 (Make proc_open accept command array). (Nikita) . Fixed bug #78208 (password_needs_rehash() with an unknown algo should always return true). (Sara) . Fixed bug #78241 (touch() does not handle dates after 2038 in PHP 64-bit). (cmb) . Fixed bug #78282 (atime and mtime mismatch). (cmb) . Fixed bug #78326 (improper memory deallocation on stream_get_contents() with fixed length buffer). (Albert Casademont) . Fixed bug #78346 (strip_tags no longer handling nested php tags). (cmb) . Fixed bug #78506 (Error in a php_user_filter::filter() is not reported). (Nikita) . Fixed bug #78549 (Stack overflow due to nested serialized input). (Nikita) . Fixed bug #78759 (array_search in $GLOBALS). (Nikita) - Testing: . Fixed bug #78684 (PCRE bug72463_2 test is sending emails on Linux). (cmb) - Tidy: . Added TIDY_TAG_* constants for HTML5 elements. (cmb) . Fixed bug #76736 (wrong reflection for tidy_get_head, tidy_get_html, tidy_get_root, and tidy_getopt) (tandre) - WDDX: . Deprecated and unbundled the WDDX extension. (cmb) - Zip: . Fixed bug #78641 (addGlob can modify given remove_path value). (cmb) 21 Nov 2019, PHP 7.3.12 - Core: . Fixed bug #78658 (Memory corruption using Closure::bindTo). (Nikita) . Fixed bug #78656 (Parse errors classified as highest log-level). (Erik Lundin) . Fixed bug #78752 (Segfault if GC triggered while generator stack frame is being destroyed). (Nikita) . Fixed bug #78689 (Closure::fromCallable() doesn't handle [Closure, '__invoke']). (Nikita) - COM: . Fixed bug #78694 (Appending to a variant array causes segfault). (cmb) - Date: . Fixed bug #70153 (\DateInterval incorrectly unserialized). (Maksim Iakunin) . Fixed bug #78751 (Serialising DatePeriod converts DateTimeImmutable). (cmb) - Iconv: . Fixed bug #78642 (Wrong libiconv version displayed). (gedas at martynas, cmb). - OpCache: . Fixed bug #78654 (Incorrectly computed opcache checksum on files with non-ascii characters). (mhagstrand) . Fixed bug #78747 (OpCache corrupts custom extension result). (Nikita) - OpenSSL: . Fixed bug #78775 (TLS issues from HTTP request affecting other encrypted connections). (Nikita) - Reflection: . Fixed bug #78697 (ReflectionClass::ImplementsInterface - inaccurate error message with traits). (villfa) - Sockets: . Fixed bug #78665 (Multicasting may leak memory). (cmb) 24 Oct 2019, PHP 7.3.11 - Core: . Fixed bug #78535 (auto_detect_line_endings value not parsed as bool). (bugreportuser) . Fixed bug #78620 (Out of memory error). (cmb, Nikita) - Exif : . Fixed bug #78442 ('Illegal component' on exif_read_data since PHP7) (Kalle) - FPM: . Fixed bug #78599 (env_path_info underflow in fpm_main.c can lead to RCE). (CVE-2019-11043) (Jakub Zelenka) . Fixed bug #78413 (request_terminate_timeout does not take effect after fastcgi_finish_request). (Sergei Turchanov) - MBString: . Fixed bug #78633 (Heap buffer overflow (read) in mb_eregi). (cmb) . Fixed bug #78579 (mb_decode_numericentity: args number inconsistency). (cmb) . Fixed bug #78609 (mb_check_encoding() no longer supports stringable objects). (cmb) - MySQLi: . Fixed bug #76809 (SSL settings aren't respected when persistent connections are used). (fabiomsouto) - Mysqlnd: . Fixed bug #78525 (Memory leak in pdo when reusing native prepared statements). (Nikita) - PCRE: . Fixed bug #78272 (calling preg_match() before pcntl_fork() will freeze child process). (Nikita) - PDO_MySQL: . Fixed bug #78623 (Regression caused by "SP call yields additional empty result set"). (cmb) - Session: . Fixed bug #78624 (session_gc return value for user defined session handlers). (bshaffer) - Standard: . Fixed bug #76342 (file_get_contents waits twice specified timeout). (Thomas Calvet) . Fixed bug #78612 (strtr leaks memory when integer keys are used and the subject string shorter). (Nikita) . Fixed bug #76859 (stream_get_line skips data if used with data-generating filter). (kkopachev) - Zip: . Fixed bug #78641 (addGlob can modify given remove_path value). (cmb) 26 Sep 2019, PHP 7.3.10 - Core: . Fixed bug #78220 (Can't access OneDrive folder). (cmb, ab) . Fixed bug #77922 (Double release of doc comment on inherited shadow property). (Nikita) . Fixed bug #78441 (Parse error due to heredoc identifier followed by digit). (cmb) . Fixed bug #77812 (Interactive mode does not support PHP 7.3-style heredoc). (cmb, Nikita) - FastCGI: . Fixed bug #78469 (FastCGI on_accept hook is not called when using named pipes on Windows). (Sergei Turchanov) - FPM: . Fixed bug #78334 (fpm log prefix message includes wrong stdout/stderr notation). (Tsuyoshi Sadakata) - Intl: . Ensure IDNA2003 rules are used with idn_to_ascii() and idn_to_utf8() when requested. (Sara) - MBString: . Fixed bug #78559 (Heap buffer overflow in mb_eregi). (cmb) - MySQLnd: . Fixed connect_attr issues and added the _server_host connection attribute. (Qianqian Bu) - ODBC: . Fixed bug #78473 (odbc_close() closes arbitrary resources). (cmb) - PDO_MySQL: . Fixed bug #41997 (SP call yields additional empty result set). (cmb) - sodium: . Fixed bug #78510 (Partially uninitialized buffer returned by sodium_crypto_generichash_init()). (Frank Denis, cmb) 29 Aug 2019, PHP 7.3.9 - Core: . Fixed bug #78363 (Buffer overflow in zendparse). (Nikita) . Fixed bug #78379 (Cast to object confuses GC, causes crash). (Dmitry) . Fixed bug #78412 (Generator incorrectly reports non-releasable $this as GC child). (Nikita) - Curl: . Fixed bug #77946 (Bad cURL resources returned by curl_multi_info_read()). (Abyr Valg) - Exif: . Fixed bug #78333 (Exif crash (bus error) due to wrong alignment and invalid cast). (Nikita) - FPM: . Fixed bug #77185 (Use-after-free in FPM master event handling). (Maksim Nikulin) - Iconv: . Fixed bug #78342 (Bus error in configure test for iconv //IGNORE). (Rainer Jung) - LiteSpeed: . Updated to LiteSpeed SAPI V7.5 (Fixed clean shutdown). (George Wang) - MBString: . Fixed bug #78380 (Oniguruma 6.9.3 fixes CVEs). (CVE-2019-13224) (Stas) - MySQLnd: . Fixed bug #78179 (MariaDB server version incorrectly detected). (cmb) . Fixed bug #78213 (Empty row pocket). (cmb) - Opcache: . Fixed bug #77191 (Assertion failure in dce_live_ranges() when silencing is used). (Nikita) - Standard: . Fixed bug #69100 (Bus error from stream_copy_to_stream (file -> SSL stream) with invalid length). (Nikita) . Fixed bug #78282 (atime and mtime mismatch). (cmb) . Fixed bug #78326 (improper memory deallocation on stream_get_contents() with fixed length buffer). (Albert Casademont) . Fixed bug #78346 (strip_tags no longer handling nested php tags). (cmb) 01 Aug 2019, PHP 7.3.8 - Core: . Added syslog.filter=raw option. (Erik Lundin) . Fixed bug #78212 (Segfault in built-in webserver). (cmb) - Date: . Fixed bug #69044 (discrepency between time and microtime). (krakjoe) . Updated timelib to 2018.02. (Derick) - EXIF: . Fixed bug #78256 (heap-buffer-overflow on exif_process_user_comment). (CVE-2019-11042) (Stas) . Fixed bug #78222 (heap-buffer-overflow on exif_scan_thumbnail). (CVE-2019-11041) (Stas) - FTP: . Fixed bug #78039 (FTP with SSL memory leak). (Nikita) - Libxml: . Fixed bug #78279 (libxml_disable_entity_loader settings is shared between requests (cgi-fcgi)). (Nikita) - LiteSpeed: . Updated to LiteSpeed SAPI V7.4.3 (increased response header count limit from 100 to 1000, added crash handler to cleanly shutdown PHP request, added CloudLinux mod_lsapi mode). (George Wang) . Fixed bug #76058 (After "POST data can't be buffered", using php://input makes huge tmp files). (George Wang) - Openssl: . Fixed bug #78231 (Segmentation fault upon stream_socket_accept of exported socket-to-stream). (Nikita) - Opcache: . Fixed bug #78189 (file cache strips last character of uname hash). (cmb) . Fixed bug #78202 (Opcache stats for cache hits are capped at 32bit NUM). (cmb) . Fixed bug #78271 (Invalid result of if-else). (Nikita) . Fixed bug #78291 (opcache_get_configuration doesn't list all directives). (Andrew Collington) . Fixed bug #78341 (Failure to detect smart branch in DFA pass). (Nikita) - PCRE: . Fixed bug #78197 (PCRE2 version check in configure fails for "##.##-xxx" version strings). (pgnet, Peter Kokot) . Fixed bug #78338 (Array cross-border reading in PCRE). (cmb) - PDO_Sqlite: . Fixed bug #78192 (SegFault when reuse statement after schema has changed). (Vincent Quatrevieux) - Phar: . Fixed bug #77919 (Potential UAF in Phar RSHUTDOWN). (cmb) - Phpdbg: . Fixed bug #78297 (Include unexistent file memory leak). (Nikita) - SQLite: . Upgraded to SQLite 3.28.0. (cmb) - Standard: . Fixed bug #78241 (touch() does not handle dates after 2038 in PHP 64-bit). (cmb) . Fixed bug #78269 (password_hash uses weak options for argon2). (Remi) 04 Jul 2019, PHP 7.3.7 - Core: . Fixed bug #76980 (Interface gets skipped if autoloader throws an exception). (Nikita) - DOM: . Fixed bug #78025 (segfault when accessing properties of DOMDocumentType). (cmb) - MySQLi: . Fixed bug #77956 (When mysqli.allow_local_infile = Off, use a meaningful error message). (Sjon Hortensius) . Fixed bug #38546 (bindParam incorrect processing of bool types). (camporter) - MySQLnd: . Fixed bug #77955 (Random segmentation fault in mysqlnd from php-fpm). (Nikita) - Opcache: . Fixed bug #78015 (Incorrect evaluation of expressions involving partials arrays in SCCP). (Nikita) . Fixed bug #78106 (Path resolution fails if opcache disabled during request). (Nikita) - OpenSSL: . Fixed bug #78079 (openssl_encrypt_ccm.phpt fails with OpenSSL 1.1.1c). (Jakub Zelenka) - phpdbg: . Fixed bug #78050 (SegFault phpdbg + opcache on include file twice). (Nikita) - Sockets: . Fixed bug #78038 (Socket_select fails when resource array contains references). (Nikita) - Sodium: . Fixed bug #78114 (segfault when calling sodium_* functions from eval). (cmb) - Standard: . Fixed bug #77135 (Extract with EXTR_SKIP should skip $this). (Craig Duncan, Dmitry) . Fixed bug #77937 (preg_match failed). (cmb, Anatol) - Zip: . Fixed bug #76345 (zip.h not found). (Michael Maroszek) 30 May 2019, PHP 7.3.6 - cURL: . Implemented FR #72189 (Add missing CURL_VERSION_* constants). (Javier Spagnoletti) - Date: . Fixed bug #77909 (DatePeriod::__construct() with invalid recurrence count value). (Ignace Nyamagana Butera) - EXIF: . Fixed bug #77988 (heap-buffer-overflow on php_jpg_get16). (CVE-2019-11040) (Stas) - FPM: . Fixed bug #77934 (php-fpm kill -USR2 not working). (Jakub Zelenka) . Fixed bug #77921 (static.php.net doesn't work anymore). (Peter Kokot) - GD: . Fixed bug #77943 (imageantialias($image, false); does not work). (cmb) . Fixed bug #77973 (Uninitialized read in gdImageCreateFromXbm). (CVE-2019-11038) (cmb) - Iconv: . Fixed bug #78069 (Out-of-bounds read in iconv.c:_php_iconv_mime_decode() due to integer overflow). (CVE-2019-11039). (maris dot adam) - JSON: . Fixed bug #77843 (Use after free with json serializer). (Nikita) - Opcache: . Fixed possible crashes, because of inconsistent PCRE cache and opcache SHM reset. (Alexey Kalinin, Dmitry) - PDO_MySQL: . Fixed bug #77944 (Wrong meta pdo_type for bigint on LLP64). (cmb) - Reflection: . Fixed bug #75186 (Inconsistent reflection of Closure:::__invoke()). (Nikita) - Session: . Fixed bug #77911 (Wrong warning for session.sid_bits_per_character). (cmb) - SOAP: . Fixed bug #77945 (Segmentation fault when constructing SoapClient with WSDL_CACHE_BOTH). (Nikita) - SPL: . Fixed bug #77024 (SplFileObject::__toString() may return array). (Craig Duncan) - SQLite: . Fixed bug #77967 (Bypassing open_basedir restrictions via file uris). (Stas) - Standard: . Fixed bug #77931 (Warning for array_map mentions wrong type). (Nikita) . Fixed bug #78003 (strip_tags output change since PHP 7.3). (cmb) 02 May 2019, PHP 7.3.5 - Core: . Fixed bug #77903 (ArrayIterator stops iterating after offsetSet call). (Nikita) - CLI: . Fixed bug #77794 (Incorrect Date header format in built-in server). (kelunik) - EXIF . Fixed bug #77950 (Heap-buffer-overflow in _estrndup via exif_process_IFD_TAG). (CVE-2019-11036) (Stas) - Interbase: . Fixed bug #72175 (Impossibility of creating multiple connections to Interbase with php 7.x). (Nikita) - Intl: . Fixed bug #77895 (IntlDateFormatter::create fails in strict mode if $locale = null). (Nikita) - LDAP: . Fixed bug #77869 (Core dump when using server controls) (mcmic) - Mail . Fixed bug #77821 (Potential heap corruption in TSendMail()). (cmb) - mbstring: . Implemented FR #72777 (Implement regex stack limits for mbregex functions). (Yasuo Ohgaki, Stas) - MySQLi: . Fixed bug #77773 (Unbuffered queries leak memory - MySQLi / mysqlnd). (Nikita) - PCRE: . Fixed bug #77827 (preg_match does not ignore \r in regex flags). (requinix, cmb) - PDO: . Fixed bug #77849 (Disable cloning of PDO handle/connection objects). (camporter) - phpdbg: . Fixed bug #76801 (too many open files). (alekitto) . Fixed bug #77800 (phpdbg segfaults on listing some conditional breakpoints). (krakjoe) . Fixed bug #77805 (phpdbg build fails when readline is shared). (krakjoe) - Reflection: . Fixed bug #77772 (ReflectionClass::getMethods(null) doesn't work). (Nikita) . Fixed bug #77882 (Different behavior: always calls destructor). (Nikita) - Standard: . Fixed bug #77793 (Segmentation fault in extract() when overwriting reference with itself). (Nikita) . Fixed bug #77844 (Crash due to null pointer in parse_ini_string with INI_SCANNER_TYPED). (Nikita) . Fixed bug #77853 (Inconsistent substr_compare behaviour with empty haystack). (Nikita) 04 Apr 2019, PHP 7.3.4 - Core: . Fixed bug #77738 (Nullptr deref in zend_compile_expr). (Laruence) . Fixed bug #77660 (Segmentation fault on break 2147483648). (Laruence) . Fixed bug #77652 (Anonymous classes can lose their interface information). (Nikita) . Fixed bug #77345 (Stack Overflow caused by circular reference in garbage collection). (Alexandru Patranescu, Nikita, Dmitry) . Fixed bug #76956 (Wrong value for 'syslog.filter' documented in php.ini). (cmb) - Apache2Handler: . Fixed bug #77648 (BOM in sapi/apache2handler/php_functions.c). (cmb) - Bcmath: . Fixed bug #77742 (bcpow() implementation related to gcc compiler optimization). (Nikita) - CLI Server: . Fixed bug #77722 (Incorrect IP set to $_SERVER['REMOTE_ADDR'] on the localhost). (Nikita) - COM: . Fixed bug #77578 (Crash when php unload). (cmb) - EXIF: . Fixed bug #77753 (Heap-buffer-overflow in php_ifd_get32s). (CVE-2019-11034) (Stas) . Fixed bug #77831 (Heap-buffer-overflow in exif_iif_add_value). (CVE-2019-11035) (Stas) - FPM: . Fixed bug #77677 (FPM fails to build on AIX due to missing WCOREDUMP). (Kevin Adler) - GD: . Fixed bug #77700 (Writing truecolor images as GIF ignores interlace flag). (cmb) - MySQLi: . Fixed bug #77597 (mysqli_fetch_field hangs scripts). (Nikita) - Opcache: . Fixed bug #77743 (Incorrect pi node insertion for jmpznz with identical successors). (Nikita) - PCRE: . Fixed bug #76127 (preg_split does not raise an error on invalid UTF-8). (Nikita) - Phar: . Fixed bug #77697 (Crash on Big_Endian platform). (Laruence) - phpdbg: . Fixed bug #77767 (phpdbg break cmd aliases listed in help do not match actual aliases). (Miriam Lauter) - sodium: . Fixed bug #77646 (sign_detached() strings not terminated). (Frank) - SQLite3: . Added sqlite3.defensive INI directive. (BohwaZ) - Standard: . Fixed bug #77664 (Segmentation fault when using undefined constant in custom wrapper). (Laruence) . Fixed bug #77669 (Crash in extract() when overwriting extracted array). (Nikita) . Fixed bug #76717 (var_export() does not create a parsable value for PHP_INT_MIN). (Nikita) . Fixed bug #77765 (FTP stream wrapper should set the directory as executable). (Vlad Temian) 07 Mar 2019, PHP 7.3.3 - Core: . Fixed bug #77589 (Core dump using parse_ini_string with numeric sections). (Laruence) . Fixed bug #77329 (Buffer Overflow via overly long Error Messages). (Dmitry) . Fixed bug #77494 (Disabling class causes segfault on member access). (Dmitry) . Fixed bug #77498 (Custom extension Segmentation fault when declare static property). (Nikita) . Fixed bug #77530 (PHP crashes when parsing `(2)::class`). (Ekin) . Fixed bug #77546 (iptcembed broken function). (gdegoulet) . Fixed bug #77630 (rename() across the device may allow unwanted access during processing). (Stas) - COM: . Fixed bug #77621 (Already defined constants are not properly reported). (cmb) . Fixed bug #77626 (Persistence confusion in php_com_import_typelib()). (cmb) - EXIF: . Fixed bug #77509 (Uninitialized read in exif_process_IFD_in_TIFF). (Stas) . Fixed bug #77540 (Invalid Read on exif_process_SOFn). (Stas) . Fixed bug #77563 (Uninitialized read in exif_process_IFD_in_MAKERNOTE). (Stas) . Fixed bug #77659 (Uninitialized read in exif_process_IFD_in_MAKERNOTE). (Stas) - Mbstring: . Fixed bug #77514 (mb_ereg_replace() with trailing backslash adds null byte). (Nikita) - MySQL . Disabled LOCAL INFILE by default, can be enabled using php.ini directive mysqli.allow_local_infile for mysqli, or PDO::MYSQL_ATTR_LOCAL_INFILE attribute for pdo_mysql. (Darek Slusarczyk) - OpenSSL: . Fixed bug #77390 (feof might hang on TLS streams in case of fragmented TLS records). (Abyl Valg, Jakub Zelenka) - PDO_OCI: . Support Oracle Database tracing attributes ACTION, MODULE, CLIENT_INFO, and CLIENT_IDENTIFIER. (Cameron Porter) - PHAR: . Fixed bug #77396 (Null Pointer Dereference in phar_create_or_parse_filename). (bishop) . Fixed bug #77586 (phar_tar_writeheaders_int() buffer overflow). (bishop) - phpdbg: . Fixed bug #76596 (phpdbg support for display_errors=stderr). (kabel) - SPL: . Fixed bug #51068 (DirectoryIterator glob:// don't support current path relative queries). (Ahmed Abdou) . Fixed bug #77431 (openFile() silently truncates after a null byte). (cmb) - Standard: . Fixed bug #77552 (Unintialized php_stream_statbuf in stat functions). (John Stevenson) . Fixed bug #77612 (setcookie() sets incorrect SameSite header if all of its options filled). (Nikita) 07 Feb 2019, PHP 7.3.2 - Core: . Fixed bug #77369 (memcpy with negative length via crafted DNS response). (Stas) . Fixed bug #77387 (Recursion detection broken when printing GLOBALS). (Laruence) . Fixed bug #77376 ("undefined function" message no longer includes namespace). (Laruence) . Fixed bug #77357 (base64_encode / base64_decode doest not work on nested VM). (Nikita) . Fixed bug #77339 (__callStatic may get incorrect arguments). (Dmitry) . Fixed bug #77317 (__DIR__, __FILE__, realpath() reveal physical path for subst virtual drive). (Anatol) . Fixed bug #77263 (Segfault when using 2 RecursiveFilterIterator). (Dmitry) . Fixed bug #77447 (PHP 7.3 built with ASAN crashes in zend_cpu_supports_avx2). (Nikita) . Fixed bug #77484 (Zend engine crashes when calling realpath in invalid working dir). (Anatol) - Curl: . Fixed bug #76675 (Segfault with H2 server push). (Pedro Magalhães) - Fileinfo: . Fixed bug #77346 (webm files incorrectly detected as application/octet-stream). (Anatol) - FPM: . Fixed bug #77430 (php-fpm crashes with Main process exited, code=dumped, status=11/SEGV). (Jakub Zelenka) - GD: . Fixed bug #73281 (imagescale(…, IMG_BILINEAR_FIXED) can cause black border). (cmb) . Fixed bug #73614 (gdImageFilledArc() doesn't properly draw pies). (cmb) . Fixed bug #77272 (imagescale() may return image resource on failure). (cmb) . Fixed bug #77391 (1bpp BMPs may fail to be loaded). (Romain Déoux, cmb) . Fixed bug #77479 (imagewbmp() segfaults with very large images). (cmb) - ldap: . Fixed bug #77440 (ldap_bind using ldaps or ldap_start_tls()=exception in libcrypto-1_1-x64.dll). (Anatol) - Mbstring: . Fixed bug #77428 (mb_ereg_replace() doesn't replace a substitution variable). (Nikita) . Fixed bug #77454 (mb_scrub() silently truncates after a null byte). (64796c6e69 at gmail dot com) - MySQLnd: . Fixed bug #77308 (Unbuffered queries memory leak). (Dmitry) . Fixed bug #75684 (In mysqlnd_ext_plugin.h the plugin methods family has no external visibility). (Anatol) - Opcache: . Fixed bug #77266 (Assertion failed in dce_live_ranges). (Laruence) . Fixed bug #77257 (value of variable assigned in a switch() construct gets lost). (Nikita) . Fixed bug #77434 (php-fpm workers are segfaulting in zend_gc_addre). (Nikita) . Fixed bug #77361 (configure fails on 64-bit AIX when opcache enabled). (Kevin Adler) . Fixed bug #77287 (Opcache literal compaction is incompatible with EXT opcodes). (Nikita) - PCRE: . Fixed bug #77338 (get_browser with empty string). (Nikita) - PDO: . Fixed bug #77273 (array_walk_recursive corrupts value types leading to PDO failure). (Nikita) - PDO MySQL: . Fixed bug #77289 (PDO MySQL segfaults with persistent connection). (Lauri Kenttä) - SOAP: . Fixed bug #77410 (Segmentation Fault when executing method with an empty parameter). (Nikita) - Sockets: . Fixed bug #76839 (socket_recvfrom may return an invalid 'from' address on MacOS). (Michael Meyer) - SPL: . Fixed bug #77298 (segfault occurs when add property to unserialized empty ArrayObject). (jhdxr) - Standard: . Fixed bug #77395 (segfault about array_multisort). (Laruence) . Fixed bug #77439 (parse_str segfaults when inserting item into existing array). (Nikita) 10 Jan 2019, PHP 7.3.1 - Core: . Fixed bug #76654 (Build failure on Mac OS X on 32-bit Intel). (Ryandesign) . Fixed bug #71041 (zend_signal_startup() needs ZEND_API). (Valentin V. Bartenev) . Fixed bug #76046 (PHP generates "FE_FREE" opcode on the wrong line). (Nikita) . Fixed bug #77291 (magic methods inherited from a trait may be ignored). (cmb) - CURL: . Fixed bug #77264 (curl_getinfo returning microseconds, not seconds). (Pierrick) - COM: . Fixed bug #77177 (Serializing or unserializing COM objects crashes). (cmb) - Exif: . Fixed bug #77184 (Unsigned rational numbers are written out as signed rationals). (Colin Basnett) - GD: . Fixed bug #77195 (Incorrect error handling of imagecreatefromjpeg()). (cmb) . Fixed bug #77198 (auto cropping has insufficient precision). (cmb) . Fixed bug #77200 (imagecropauto(…, GD_CROP_SIDES) crops left but not right). (cmb) . Fixed bug #77269 (efree() on uninitialized Heap data in imagescale leads to use-after-free). (cmb) . Fixed bug #77270 (imagecolormatch Out Of Bounds Write on Heap). (cmb) - MBString: . Fixed bug #77367 (Negative size parameter in mb_split). (Stas) . Fixed bug #77370 (Buffer overflow on mb regex functions - fetch_token). (Stas) . Fixed bug #77371 (heap buffer overflow in mb regex functions - compile_string_node). (Stas) . Fixed bug #77381 (heap buffer overflow in multibyte match_at). (Stas) . Fixed bug #77382 (heap buffer overflow due to incorrect length in expand_case_fold_string). (Stas) . Fixed bug #77385 (buffer overflow in fetch_token). (Stas) . Fixed bug #77394 (Buffer overflow in multibyte case folding - unicode). (Stas) . Fixed bug #77418 (Heap overflow in utf32be_mbc_to_code). (Stas) - OCI8: . Fixed bug #76804 (oci_pconnect with OCI_CRED_EXT not working). (KoenigsKind) . Added oci_set_call_timeout() for call timeouts. . Added oci_set_db_operation() for the DBOP end-to-end-tracing attribute. - Opcache: . Fixed bug #77215 (CFG assertion failure on multiple finalizing switch frees in one block). (Nikita) . Fixed bug #77275 (OPcache optimization problem for ArrayAccess->offsetGet). (Nikita) - PCRE: . Fixed bug #77193 (Infinite loop in preg_replace_callback). (Anatol) - PDO: . Handle invalid index passed to PDOStatement::fetchColumn() as error. (Sergei Morozov) - Phar: . Fixed bug #77247 (heap buffer overflow in phar_detect_phar_fname_ext). (Stas) - Soap: . Fixed bug #77088 (Segfault when using SoapClient with null options). (Laruence) - Sockets: . Fixed bug #77136 (Unsupported IPV6_RECVPKTINFO constants on macOS). (Mizunashi Mana) - Sodium: . Fixed bug #77297 (SodiumException segfaults on PHP 7.3). (Nikita, Scott) - SPL: . Fixed bug #77359 (spl_autoload causes segfault). (Lauri Kenttä) . Fixed bug #77360 (class_uses causes segfault). (Lauri Kenttä) - SQLite3: . Fixed bug #77051 (Issue with re-binding on SQLite3). (BohwaZ) - Xmlrpc: . Fixed bug #77242 (heap out of bounds read in xmlrpc_decode()). (cmb) . Fixed bug #77380 (Global out of bounds read in xmlrpc base64 code). (Stas) 06 Dec 2018, PHP 7.3.0 - Core: . Improved PHP GC. (Dmitry, Nikita) . Redesigned the old ext_skel program written in PHP, run: 'php ext_skel.php' for all options. This means there are no dependencies, thus making it work on Windows out of the box. (Kalle) . Removed support for BeOS. (Kalle) . Add PHP_VERSION to phpinfo()