<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/php-git.git, branch php-5.5.10</title>
<subtitle>git.php.net: repository/php-src.git
</subtitle>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/'/>
<entry>
<title>5.5.10 final</title>
<updated>2014-03-05T10:18:00+00:00</updated>
<author>
<name>Julien Pauli</name>
<email>jpauli@php.net</email>
</author>
<published>2014-03-05T10:18:00+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=3156580a34b947e4325fdd165015904153790c39'/>
<id>3156580a34b947e4325fdd165015904153790c39</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>NEWS for cherry-picked CVE patches</title>
<updated>2014-03-05T10:08:11+00:00</updated>
<author>
<name>Julien Pauli</name>
<email>jpauli@php.net</email>
</author>
<published>2014-03-05T10:08:11+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=eb63f8c2a66906a617d94667f0b54f1544ac93d9'/>
<id>eb63f8c2a66906a617d94667f0b54f1544ac93d9</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Fixed Bug #66815 imagecrop(): insufficient fix for NULL defer CVE-2013-7327</title>
<updated>2014-03-05T09:53:57+00:00</updated>
<author>
<name>Remi Collet</name>
<email>remi@php.net</email>
</author>
<published>2014-03-05T09:40:36+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=0880851f004ba8ad793b9fb68e3ee6755245a0ba'/>
<id>0880851f004ba8ad793b9fb68e3ee6755245a0ba</id>
<content type='text'>
This amends commit 8f4a537, which aimed to correct NULL dereference because of
missing check of gdImageCreateTrueColor() / gdImageCreate() return value.  That
commit checks for negative crop rectangle width and height, but
gdImageCreate*() can also return NULL when width * height overflows.  Hence
NULL deref is still possible, as gdImageSaveAlpha() and gdImagePaletteCopy()
is called before dst == NULL check.

This moves NULL check to happen right after gdImageCreate*().  It also removes
width and height check before gdImageCreate*(), as the same check is done by
image create functions (with an extra warning).

From thoger redhat com
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This amends commit 8f4a537, which aimed to correct NULL dereference because of
missing check of gdImageCreateTrueColor() / gdImageCreate() return value.  That
commit checks for negative crop rectangle width and height, but
gdImageCreate*() can also return NULL when width * height overflows.  Hence
NULL deref is still possible, as gdImageSaveAlpha() and gdImagePaletteCopy()
is called before dst == NULL check.

This moves NULL check to happen right after gdImageCreate*().  It also removes
width and height check before gdImageCreate*(), as the same check is done by
image create functions (with an extra warning).

From thoger redhat com
</pre>
</div>
</content>
</entry>
<entry>
<title>Fixed Bug #66820 out-of-bounds memory access in fileinfo</title>
<updated>2014-03-05T09:53:00+00:00</updated>
<author>
<name>Remi Collet</name>
<email>remi@php.net</email>
</author>
<published>2014-03-04T19:32:52+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=53c6b594f5a0dc1650acfef37d6282d15fea593f'/>
<id>53c6b594f5a0dc1650acfef37d6282d15fea593f</id>
<content type='text'>
Upstream fix:
https://github.com/glensc/file/commit/447558595a3650db2886cd2f416ad0beba965801

Notice, test changed, with upstream agreement:
-define OFFSET_OOB(n, o, i)	((n) &lt; (o) || (i) &gt;= ((n) - (o)))
+define OFFSET_OOB(n, o, i)	((n) &lt; (o) || (i) &gt;  ((n) - (o)))
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Upstream fix:
https://github.com/glensc/file/commit/447558595a3650db2886cd2f416ad0beba965801

Notice, test changed, with upstream agreement:
-define OFFSET_OOB(n, o, i)	((n) &lt; (o) || (i) &gt;= ((n) - (o)))
+define OFFSET_OOB(n, o, i)	((n) &lt; (o) || (i) &gt;  ((n) - (o)))
</pre>
</div>
</content>
</entry>
<entry>
<title>Improves fix for memory leak, keep in sync with upstream.</title>
<updated>2014-03-05T09:52:29+00:00</updated>
<author>
<name>Remi Collet</name>
<email>remi@php.net</email>
</author>
<published>2014-03-04T12:41:37+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=1677be7a30e5d4bf7dd452f9a76c277238f27b6f'/>
<id>1677be7a30e5d4bf7dd452f9a76c277238f27b6f</id>
<content type='text'>
Previous fix:
http://git.php.net/?p=php-src.git;a=commitdiff;h=10eb0070700382f966bf260e44135e1f724a15d2

Upstream fix:
https://github.com/glensc/file/commit/c0c0032b9e9eb57b91fefef905a3b018bab492d9
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Previous fix:
http://git.php.net/?p=php-src.git;a=commitdiff;h=10eb0070700382f966bf260e44135e1f724a15d2

Upstream fix:
https://github.com/glensc/file/commit/c0c0032b9e9eb57b91fefef905a3b018bab492d9
</pre>
</div>
</content>
</entry>
<entry>
<title>fixed leak introduced after CVE/upgrade</title>
<updated>2014-03-05T09:52:05+00:00</updated>
<author>
<name>Anatol Belski</name>
<email>ab@php.net</email>
</author>
<published>2014-02-20T17:53:53+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=61bcea70199b94d057ff60fb666a279376c8af2d'/>
<id>61bcea70199b94d057ff60fb666a279376c8af2d</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>5.5.10RC1</title>
<updated>2014-02-18T16:14:48+00:00</updated>
<author>
<name>Julien Pauli</name>
<email>jpauli@php.net</email>
</author>
<published>2014-02-18T16:14:48+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=46996a68a3996777bac94cc4af4935e024804267'/>
<id>46996a68a3996777bac94cc4af4935e024804267</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Set fileinfo version to 1.0.5 (as in php 5.4, no diff)</title>
<updated>2014-02-18T12:57:53+00:00</updated>
<author>
<name>Remi Collet</name>
<email>remi@php.net</email>
</author>
<published>2014-02-18T12:57:53+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=bd8cd98d6d70ac50dc1de350970ed9ea479895db'/>
<id>bd8cd98d6d70ac50dc1de350970ed9ea479895db</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>NEWS</title>
<updated>2014-02-18T12:57:28+00:00</updated>
<author>
<name>Remi Collet</name>
<email>remi@php.net</email>
</author>
<published>2014-02-18T12:57:28+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=a6ad3a558a1e005a30b5c2ecd83ebf4084b70560'/>
<id>a6ad3a558a1e005a30b5c2ecd83ebf4084b70560</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge branch 'PHP-5.4' into PHP-5.5</title>
<updated>2014-02-18T12:57:10+00:00</updated>
<author>
<name>Remi Collet</name>
<email>remi@php.net</email>
</author>
<published>2014-02-18T12:57:10+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=bdd65b578cdba232ff6ffa6e4bf05ff6aaff6d51'/>
<id>bdd65b578cdba232ff6ffa6e4bf05ff6aaff6d51</id>
<content type='text'>
* PHP-5.4:
  NEWS
  Fixed Bug #66731 file: infinite recursion
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* PHP-5.4:
  NEWS
  Fixed Bug #66731 file: infinite recursion
</pre>
</div>
</content>
</entry>
</feed>
