PHP 5.3.1 released! LockedRSS

0 replies

Last post Nov 22, 2009 01:59 PM by pierrejoye

  • PHP 5.3.1 released!

    Nov 22, 2009 01:59 PM|pierrejoye|LINK

    <div>

    The PHP development team would like to announce the immediate availability of PHP 5.3.1. This release focuses on improving the stability of the PHP 5.3.x branch with over 100 bug fixes, some of which are security related. All users of PHP are encouraged to upgrade to this release.

    Security Enhancements and Fixes in PHP 5.3.1:

    • Added "max_file_uploads" INI directive, which can be set to limit the number of file uploads per-request to 20 by default, to prevent possible DOS via temporary file exhaustion.
    • Added missing sanity checks around exif processing.
    • Fixed a safe_mode bypass in tempnam().
    • Fixed a open_basedir bypass in posix_mkfifo().
    • Fixed failing safe_mode_include_dir.

    Further details about the PHP 5.3.1 release can be found in the release announcement, and the full list of changes are available in the ChangeLog.

    The OpenSSL library has been updated to 0.9.8l, which fixes important bugs fixes (see the OpenSSL website for details.

    </div>

    PHP FastCGI iis