Home » Releases » 5.6 » 5.6.40 »

PHP 5.6.27

PHP 5.6 is no longer officially supported by the PHP project.

Official support refers to that provided direct by the PHP Project.

If you install PHP via third-party packages, support timelines may be different. Please read the Release Support Policy for more information.

The latest release of PHP 5.6 is 5.6.40.

Source Code

Change Log

  • core

    • Fixed bug #73025 (Heap Buffer Overflow in virtual_popen of zend_virtual_cwd.c).
      cmb
    • Fixed bug #73058 (crypt broken when salt is 'too' long).
      Anatol
    • Fixed bug #72703 (Out of bounds global memory read in BF_crypt triggered by password_verify).
      Anatol
    • Fixed bug #73189 (Memcpy negative size parameter php_resolve_path).
      Stas
    • Fixed bug #73147 (Use After Free in unserialize()).
      Stas
  • bcmath

    • Fixed bug #73190 (memcpy negative parameter _bc_new_num_ex).
      Stas
  • dom

    • Fixed bug #73150 (missing NULL check in dom_document_save_html).
      Stas
  • ereg

    • Fixed bug #73284 (heap overflow in php_ereg_replace function).
      Stas
  • filter

    • Fixed bug #72972 (Bad filter for the flags FILTER_FLAG_NO_RES_RANGE and FILTER_FLAG_NO_PRIV_RANGE).
      julien
    • Fixed bug #67167 (Wrong return value from FILTER_VALIDATE_BOOLEAN, FILTER_NULL_ON_FAILURE).
      levim
      cmb
    • Fixed bug #73054 (default option ignored when object passed to int filter).
      cmb
  • gd

    • Fixed bug #67325 (imagetruecolortopalette: white is duplicated in palette).
      cmb
    • Fixed bug #50194 (imagettftext broken on transparent background w/o alphablending).
      cmb
    • Fixed bug #73003 (Integer Overflow in gdImageWebpCtx of gd_webp.c).
      trylab
      cmb
    • Fixed bug #53504 (imagettfbbox gives incorrect values for bounding box).
      Mark Plomer
      cmb
    • Fixed bug #73157 (imagegd2() ignores 3rd param if 4 are given).
      cmb
    • Fixed bug #73155 (imagegd2() writes wrong chunk sizes on boundaries).
      cmb
    • Fixed bug #73159 (imagegd2(): unrecognized formats may result in corrupted files).
      cmb
    • Fixed bug #73161 (imagecreatefromgd2() may leak memory).
      cmb
  • intl

    • Fixed bug #73218 (add mitigation for ICU int overflow).
      Stas
  • imap

    • Fixed bug #73208 (integer overflow in imap_8bit caused heap corruption).
      Stas
  • mbstring

    • Fixed bug #72994 (mbc_to_code() out of bounds read).
      Laruence
      cmb
    • Fixed bug #66964 (mb_convert_variables() cannot detect recursion).
      Yasuo
    • Fixed bug #72992 (mbstring.internal_encoding doesn't inherit default_charset).
      Yasuo
    • Fixed bug #73082 (string length overflow in mb_encode_* function).
      Stas
  • pcre

    • Fixed bug #73174 (heap overflow in php_pcre_replace_impl).
      Stas
  • opcache

    • Fixed bug #72590 (Opcache restart with kill_all_lockers does not work).
      Keyur) (julien backport
  • openssl

    • Fixed bug #73072 (Invalid path SNI_server_certs causes segfault).
      Jakub Zelenka
    • Fixed bug #73275 (crash in openssl_encrypt function).
      Stas
    • Fixed bug #73276 (crash in openssl_random_pseudo_bytes function).
      Stas
  • session

    • Fixed bug #68015 (Session does not report invalid uid for files save handler).
      Yasuo
    • Fixed bug #73100 (session_destroy null dereference in ps_files_path_create).
      cmb
  • simplexml

    • Fixed bug #73293 (NULL pointer dereference in SimpleXMLElement::asXML()).
      Stas
  • spl

    • Fixed bug #73073 (CachingIterator null dereference when convert to string).
      Stas
  • standard

    • Fixed bug #73240 (Write out of bounds at number_format).
      Stas
    • Fixed bug #73017 (memory corruption in wordwrap function).
      Stas
  • stream

    • Fixed bug #73069 (readfile() mangles files larger than 2G).
      Laruence
  • zip

    • Fixed bug #70752 (Depacking with wrong password leaves 0 length files).
      cmb

PHP 5.6


  Represents a security release