Home » Releases » 5.4 » 5.4.45 »

PHP 5.4.20

PHP 5.4 is no longer officially supported by the PHP project.

Official support refers to that provided direct by the PHP Project.

If you install PHP via third-party packages, support timelines may be different. Please read the Release Support Policy for more information.

The latest release of PHP 5.4 is 5.4.45.

Source Code

Change Log

  • core

    • Fixed bug #60598 (cli/apache sapi segfault on objects manipulation).
      Laruence
    • Fixed bug #65579 (Using traits with get_class_methods causes segfault).
      Adam
    • Fixed bug #65490 (Duplicate calls to get lineno & filename for DTRACE_FUNCTION_*).
      Chris Jones
    • Fixed bug #65483 (quoted-printable encode stream filter incorrectly encoding spaces).
      Michael M Slusarz
    • Fixed bug #65481 (shutdown segfault due to serialize) (Mike)
    • Fixed bug #65470 (Segmentation fault in zend_error() with --enable-dtrace).
      Chris Jones
      Kris Van Hees
    • Fixed bug #65372 (Segfault in gc_zval_possible_root when return reference fails).
      Laruence
    • Fixed bug #65304 (Use of max int in array_sum).
      Laruence
    • Fixed bug #65291 (get_defined_constants() causes PHP to crash in a very limited case).
      Arpad
    • Fixed bug #65225 (PHP_BINARY incorrectly set).
      Patrick Allaert
    • Improved fix for bug #63186 (compile failure on netbsd).
      Matteo
    • Fixed bug #62692 (PHP fails to build with DTrace).
      Chris Jones
      Kris Van Hees
    • Fixed bug #61759 (class_alias() should accept classes with leading backslashes).
      Julien
    • Fixed bug #61345 (CGI mode - make install don't work).
      Michael Heimpold
    • Cherry-picked some DTrace build commits (allowing builds on Linux, bug #62691, and bug #63706) from PHP 5.5 branch
    • Fixed bug #61268 (--enable-dtrace leads make to clobber Zend/zend_dtrace.d) (Chris Jones)
  • curl

    • Fixed bug #65458 (curl memory leak).
      Adam
  • datetime

    • Fixed bug #65554 (createFromFormat broken when weekday name is followed by some delimiters). (Valentin Logvinskiy, Stas).
    • Fixed bug #65564 (stack-buffer-overflow in DateTimeZone stuff caught by AddressSanitizer). (Remi).
  • openssl

    • Fixed bug #64802 (openssl_x509_parse fails to parse subject properly in some cases).
      Mark Jones
  • session

    • Fixed bug #62129 (rfc1867 crashes php even though turned off).
      gxd305 at gmail dot com
    • Fixed bug #50308 (session id not appended properly for empty anchor tags).
      Arpad
    • Fixed possible buffer overflow under Windows. Note: Not a security fix.
      Yasuo
    • Changed session.auto_start to PHP_INI_PERDIR.
      Yasuo
  • soap

    • Fixed bug #65018 (SoapHeader problems with SoapServer).
      Dmitry
  • spl

    • Fixed bug #65328 (Segfault when getting SplStack object Value).
      Laruence
  • pdo

    • Fixed bug #64953 (Postgres prepared statement positional parameter casting).
      Mike
  • phar

    • Fixed bug #65028 (Phar::buildFromDirectory creates corrupt archives for some specific contents).
      Stas
  • pgsql

    • Fixed bug #65336 (pg_escape_literal/identifier() silently returns false).
      Yasuo
    • Fixed bug #62978 (Disallow possible SQL injections with pg_select()/pg_update() /pg_delete()/pg_insert()).
      Yasuo
  • zlib

    • Fixed bug #65391 (Unable to send vary header user-agent when ob_start('ob_gzhandler') is called) (Mike)

PHP 5.4


  Represents a security release