<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/php-git.git, branch php-7.1.30</title>
<subtitle>git.php.net: repository/php-src.git
</subtitle>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/'/>
<entry>
<title>set versions for release</title>
<updated>2019-05-28T07:36:28+00:00</updated>
<author>
<name>Joe Watkins</name>
<email>krakjoe@php.net</email>
</author>
<published>2019-05-28T07:36:28+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=835993236936bb4791ba0a705382072e65e1219a'/>
<id>835993236936bb4791ba0a705382072e65e1219a</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix bug #77967 - Bypassing open_basedir restrictions via file uris</title>
<updated>2019-05-28T01:48:48+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2019-05-28T01:04:00+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=c34895e837b50213c2bb201c612904342d2bd216'/>
<id>c34895e837b50213c2bb201c612904342d2bd216</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix bug #77988 - heap-buffer-overflow on php_jpg_get16</title>
<updated>2019-05-28T00:28:09+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2019-05-28T00:16:29+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=73ff4193be24192c894dc0502d06e2b2db35eefb'/>
<id>73ff4193be24192c894dc0502d06e2b2db35eefb</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Update NEWS</title>
<updated>2019-05-27T23:48:32+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2019-05-27T23:48:32+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=16e037bd46359a31f218ee220ff09f1c3270e489'/>
<id>16e037bd46359a31f218ee220ff09f1c3270e489</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix bug #78069 - Out-of-bounds read in iconv.c:_php_iconv_mime_decode() due to integer overflow</title>
<updated>2019-05-27T23:32:42+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2019-05-27T23:32:42+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=7cf7148a8f8f4f55fb04de2a517d740bb6253eac'/>
<id>7cf7148a8f8f4f55fb04de2a517d740bb6253eac</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix #77973: Uninitialized read in gdImageCreateFromXbm</title>
<updated>2019-05-27T23:11:32+00:00</updated>
<author>
<name>Christoph M. Becker</name>
<email>cmbecker69@gmx.de</email>
</author>
<published>2019-05-06T08:18:51+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=ed6dee9a198c904ad5e03113e58a2d2c200f5184'/>
<id>ed6dee9a198c904ad5e03113e58a2d2c200f5184</id>
<content type='text'>
We have to ensure that `sscanf()` does indeed read a hex value here,
and bail out otherwise.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
We have to ensure that `sscanf()` does indeed read a hex value here,
and bail out otherwise.
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix bug #77950 - Heap-buffer-overflow in _estrndup via exif_process_IFD_TAG</title>
<updated>2019-04-30T07:05:23+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2019-04-30T06:38:12+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=f80ad18afae2230c2c1802c7d829100af646874e'/>
<id>f80ad18afae2230c2c1802c7d829100af646874e</id>
<content type='text'>
I do not completely understand what is going on there, but I am pretty
sure dir_entry &lt;= offset_base if not a normal situation, so we better not
to rely on such dir_entry.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
I do not completely understand what is going on there, but I am pretty
sure dir_entry &lt;= offset_base if not a normal situation, so we better not
to rely on such dir_entry.
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix #77821: Potential heap corruption in TSendMail()</title>
<updated>2019-04-30T05:08:19+00:00</updated>
<author>
<name>Christoph M. Becker</name>
<email>cmbecker69@gmx.de</email>
</author>
<published>2019-03-29T10:12:09+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=6c631ccfef94f93259d474682f8bfa803e163c87'/>
<id>6c631ccfef94f93259d474682f8bfa803e163c87</id>
<content type='text'>
`zend_string_tolower()` returns a copy (not a duplicate) of the given
string, if it is already in lower case.  In this case we must not not
`zend_string_free()` both strings.  The cleanest solution is to call
` zend_string_release()` on both strings, which properly handles the
refcount.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
`zend_string_tolower()` returns a copy (not a duplicate) of the given
string, if it is already in lower case.  In this case we must not not
`zend_string_free()` both strings.  The cleanest solution is to call
` zend_string_release()` on both strings, which properly handles the
refcount.
</pre>
</div>
</content>
</entry>
<entry>
<title>Always use ZEND_SECURE_ZERO() when cleaning up data</title>
<updated>2019-04-07T01:15:42+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2019-04-07T01:15:42+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=588db7cecf6cf8b351de0fecdfc7de70f54bf1b1'/>
<id>588db7cecf6cf8b351de0fecdfc7de70f54bf1b1</id>
<content type='text'>
Optimizing compilers have an annoying tendency to throw out
memsets over data that they think aren't used anymore. Apply secure
zero-out in cases where this has potential to happen.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Optimizing compilers have an annoying tendency to throw out
memsets over data that they think aren't used anymore. Apply secure
zero-out in cases where this has potential to happen.
</pre>
</div>
</content>
</entry>
<entry>
<title>bump versions after release</title>
<updated>2019-04-02T14:50:20+00:00</updated>
<author>
<name>Joe Watkins</name>
<email>krakjoe@php.net</email>
</author>
<published>2019-04-02T14:50:20+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=731eeb8decf3cf0197e7fd6989b5fd2befcdb3e5'/>
<id>731eeb8decf3cf0197e7fd6989b5fd2befcdb3e5</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
</feed>
