PHP 5.6 is no longer officially supported by the PHP project.
Official support refers to that provided direct by the PHP Project.
If you install PHP via third-party packages, support timelines may be different.
Please read the Release Support Policy for more information.
The latest release of PHP 5.6 is
5.6.40.
Source Code
Change Log
-
core
-
Fixed bug
#71936 (Segmentation fault destroying HTTP_RAW_POST_DATA).
mike dot laspina at gmail dot com
Remi
-
Fixed bug
#72496 (Cannot declare public method with signature incompatible with parent private method).
-
Fixed bug
#72138 (Integer Overflow in Length of String-typed ZVAL).
-
Fixed bug
#72513 (Stack-based buffer overflow vulnerability in virtual_file_ex).
loianhtuan at gmail dot com
-
Fixed bug
#72562 (Use After Free in unserialize() with Unexpected Session Deserialization).
taoguangchen at icloud dot com
-
Fixed bug
#72573 (HTTP_PROXY is improperly trusted by some PHP libraries and applications). (CVE-2016-5385)
-
bz2
-
Fixed bug
#72447 (Type Confusion in php_bz2_filter_create()). (gogil at stealien dot com).
-
Fixed bug
#72613 (Inadequate error handling in bzread()).
-
date
-
Fixed bug
#66836 (DateTime::createFromFormat 'U' with pre 1970 dates fails parsing).
-
exif
-
Fixed bug
#50845 (exif_read_data() returns corrupted exif headers).
-
Fixed bug
#72603 (Out of bound read in exif_process_IFD_in_MAKERNOTE).
-
Fixed bug
#72618 (NULL Pointer Dereference in exif_process_user_comment).
-
gd
-
Fixed bug
#43475 (Thick styled lines have scrambled patterns).
-
Fixed bug
#53640 (XBM images require width to be multiple of 8).
-
Fixed bug
#64641 (imagefilledpolygon doesn't draw horizontal line).
-
Fixed bug
#72512 (gdImageTrueColorToPaletteBody allows arbitrary write/read access).
-
Fixed bug
#72519 (imagegif/output out-of-bounds access).
-
Fixed bug
#72558 (Integer overflow error within _gdContributionsAlloc()). (CVE-2016-6207)
-
intl
-
Fixed bug
#72533 (locale_accept_from_http out-of-bounds access).
-
openssl
-
Fixed bug
#71915 (openssl_random_pseudo_bytes is not fork-safe).
-
Fixed bug
#72336 (openssl_pkey_new does not fail for invalid DSA params).
-
snmp
-
Fixed bug
#72479 (Use After Free Vulnerability in SNMP with GC and unserialize()).
taoguangchen at icloud dot com
-
spl
-
Fixed bug
#55701 (GlobIterator throws LogicException).
-
sqlite3
-
Fixed bug
#70628 (Clearing bindings on an SQLite3 statement doesn't work).
-
streams
-
Fixed bug
#72439 (Stream socket with remote address leads to a segmentation fault).
-
xmlrpc
-
Fixed bug
#72606 (heap-buffer-overflow (write) simplestring_addn simplestring.c).
-
zip
-
Fixed bug
#72520 (Stack-based buffer overflow vulnerability in php_stream_zip_opener).
loianhtuan at gmail dot com