Home » Releases » 5.5 » 5.5.38 »

PHP 5.5.25

PHP 5.5 is no longer officially supported by the PHP project.

Official support refers to that provided direct by the PHP Project.

If you install PHP via third-party packages, support timelines may be different. Please read the Release Support Policy for more information.

The latest release of PHP 5.5 is 5.5.38.

Source Code

Change Log

  • core

    • Fixed bug #69364 (PHP Multipart/form-data remote dos Vulnerability). (CVE-2015-4024)
      Stas
    • Fixed bug #69403 (str_repeat() sign mismatch based memory corruption).
      Stas
    • Fixed bug #69418 (CVE-2006-7243 fix regressions in 5.4+). (CVE-2015-4025)
      Stas
    • Fixed bug #69522 (heap buffer overflow in unpack()).
      Stas
    • Fixed bug #69467 (Wrong checked for the interface by using Trait).
      Laruence
    • Fixed bug #69420 (Invalid read in zend_std_get_method).
      Laruence
    • Fixed bug #60022 ("use statement [...] has no effect" depends on leading backslash).
      Nikita
    • Fixed bug #67314 (Segmentation fault in gc_remove_zval_from_buffer).
      Dmitry
    • Fixed bug #68652 (segmentation fault in destructor).
      Dmitry
    • Fixed bug #69419 (Returning compatible sub generator produces a warning).
      Nikita
    • Fixed bug #69472 (php_sys_readlink ignores misc errors from GetFinalPathNameByHandleA).
      Jan Starke
  • ftp

    • Fixed bug #69545 (Integer overflow in ftp_genlist() resulting in heap overflow). (CVE-2015-4022)
      Stas
  • odbc

    • Fixed bug #69354 (Incorrect use of SQLColAttributes with ODBC 3.0).
      Anatol
    • Fixed bug #69474 (ODBC: Query with same field name from two tables returns incorrect result).
      Anatol
    • Fixed bug #69381 (out of memory with sage odbc driver).
      Frederic Marchall
      Anatol Belski
  • openssl

    • Fixed bug #69402 (Reading empty SSL stream hangs until timeout).
      Daniel Lowrey
  • pcntl

    • Fixed bug #68598 (pcntl_exec() should not allow null char). (CVE-2015-4026)
      Stas
  • phar

    • Fixed bug #69453 (Memory Corruption in phar_parse_tarfile when entry filename starts with null). (CVE-2015-4021)
      Stas

PHP 5.5


  Represents a security release