SEARCH
NEW RPMS
DIRECTORIES
ABOUT
FAQ
VARIOUS
BLOG

 
 
Changelog for php7-devel-7.4.33-150200.3.46.2.x86_64.rpm :

* Thu Nov 03 2022 pgajdosAATTsuse.com- version update to 7.4.33 [bsc#1204577][bsc#1204979] 03 Nov 2022 GD: Fixed bug #81739: OOB read due to insufficient input validation in imageloadfont(). (CVE-2022-31630) Hash: Fixed bug #81738: buffer overflow in hash_update() on long parameter. (CVE-2022-37454)
* Mon Oct 03 2022 pgajdosAATTsuse.com- version update to 7.4.32 [jsc#SLE-23639] Version 7.4.32 29 Sep 2022 Core: Fixed bug #81726: phar wrapper: DOS when using quine gzip file. (CVE-2022-31628) Fixed bug #81727: Don\'t mangle HTTP variable names that clash with ones that have a specific semantic meaning. (CVE-2022-31629) Version 7.4.30 09 Jun 2022 mysqlnd: Fixed bug #81719: mysqlnd/pdo password buffer overflow. (CVE-2022-31626) pgsql: Fixed bug #81720: Uninitialized array in pg_query_params(). (CVE-2022-31625) Version 7.4.29 14 Apr 2022 Core: No source changes to this release. This update allows for re-building the Windows binaries against upgraded dependencies which have received security updates. Date: Updated to latest IANA timezone database (2022a). Version 7.4.28 17 Feb 2022 Filter: Fix #81708: UAF due to php_filter_float() failing for ints (CVE-2021-21708) Version 7.4.27 16 Dec 2021 Core: Fixed bug #81626 (Error on use static:: in __сallStatic() wrapped to Closure::fromCallable()). FPM: Fixed bug #81513 (Future possibility for heap overflow in FPM zlog). GD: Fixed bug #71316 (libpng warning from imagecreatefromstring). OpenSSL: Fixed bug #75725 (./configure: detecting RAND_egd). PCRE: Fixed bug #74604 (Out of bounds in php_pcre_replace_impl). Standard: Fixed bug #81618 (dns_get_record fails on FreeBSD for missing type). Fixed bug #81659 (stream_get_contents() may unnecessarily overallocate). Version 7.4.26 18 Nov 2021 Core: Fixed bug #81518 (Header injection via default_mimetype / default_charset). Date: Fixed bug #81500 (Interval serialization regression since 7.3.14 / 7.4.2). MBString: Fixed bug #76167 (mbstring may use pointer from some previous request). MySQLi: Fixed bug #81494 (Stopped unbuffered query does not throw error). PCRE: Fixed bug #81424 (PCRE2 10.35 JIT performance regression). Streams: Fixed bug #54340 (Memory corruption with user_filter). XML: Fixed bug #79971 (special character is breaking the path in xml function). (CVE-2021-21707) Version 7.4.25 21 Oct 2021 DOM: Fixed bug #81433 (DOMElement::setIdAttribute() called twice may remove ID). FFI: Fixed bug #79576 (\"TYPE
*\" shows unhelpful message when type is not defined). Fileinfo: Fixed bug #78987 (High memory usage during encoding detection). Filter: Fixed bug #61700 (FILTER_FLAG_IPV6/FILTER_FLAG_NO_PRIV|RES_RANGE failing). FPM: Fixed bug #81026 (PHP-FPM oob R/W in root process leading to privilege escalation) (CVE-2021-21703). SPL: Fixed bug #80663 (Recursive SplFixedArray::setSize() may cause double-free). Streams: Fixed bug #81475 (stream_isatty emits warning with attached stream wrapper). XML: Fixed bug #70962 (XML_OPTION_SKIP_WHITE strips embedded whitespace). Zip: Fixed bug #81490 (ZipArchive::extractTo() may leak memory). Fixed bug #77978 (Dirname ending in colon unzips to wrong dir). Version 7.4.24 23 Sep 2021 Core: Fixed bug #81302 (Stream position after stream filter removed). Fixed bug #81346 (Non-seekable streams don\'t update position after write). Fixed bug #73122 (Integer Overflow when concatenating strings). (CVE-2017-8923) GD: Fixed bug #53580 (During resize gdImageCopyResampled cause colors change). Opcache: Fixed bug #81353 (segfault with preloading and statically bound closure). Shmop: Fixed bug #81407 (shmop_open won\'t attach and causes php to crash). Standard: Fixed bug #71542 (disk_total_space does not work with relative paths). Fixed bug #81400 (Unterminated string in dns_get_record() results). SysVMsg: Fixed bug #78819 (Heap Overflow in msg_send). XML: Fixed bug #81351 (xml_parse may fail, but has no error code). Zip: Fixed bug #81420 (ZipArchive::extractTo extracts outside of destination). (CVE-2021-21706) Version 7.4.23 26 Aug 2021 Core: Fixed bug #72595 (php_output_handler_append illegal write access). Fixed bug #66719 (Weird behaviour when using get_called_class() with call_user_func()). Fixed bug #81305 (Built-in Webserver Drops Requests With \"Upgrade\" Header). BCMath: Fixed bug #78238 (BCMath returns \"-0\"). CGI: Fixed bug #80849 (HTTP Status header truncation). GD: Fixed bug #51498 (imagefilledellipse does not work for large circles). MySQLi: Fixed bug #74544 (Integer overflow in mysqli_real_escape_string()). OpenSSL: Fixed bug #81327 (Error build openssl extension on php 7.4.22). PDO_ODBC: Fixed bug #81252 (PDO_ODBC doesn\'t account for SQL_NO_TOTAL). Phar: Fixed bug #81211: Symlinks are followed when creating PHAR archive.(cmb) Shmop: Fixed bug #81283 (shmop can\'t read beyond 2147483647 bytes). Standard: Fixed bug #72146 (Integer overflow on substr_replace). Fixed bug #81265 (getimagesize returns 0 for 256px ICO images). Fixed bug #74960 (Heap buffer overflow via str_repeat). Streams: Fixed bug #81294 (Segfault when removing a filter). Version 7.4.22 29 Jul 2021 Core: Fixed bug #81145 (copy() and stream_copy_to_stream() fail for +4GB files). Fixed bug #81163 (incorrect handling of indirect vars in __sleep). Fixed bug #80728 (PHP built-in web server resets timeout when it can kill the process). Fixed bug #73630 (Built-in Webserver - overwrite $_SERVER[\'request_uri\']). Fixed bug #80173 (Using return value of zend_assign_to_variable() is not safe). Fixed bug #73226 (--r[fcez] always return zero exit code). Intl: Fixed bug #72809 (Locale::lookup() wrong result with canonicalize option). Fixed bug #68471 (IntlDateFormatter fails for \"GMT+00:00\" timezone). Fixed bug #74264 (grapheme_strrpos() broken for negative offsets). OpenSSL: Fixed bug #52093 (openssl_csr_sign truncates $serial). PCRE: Fixed bug #81101 (PCRE2 10.37 shows unexpected result). Fixed bug #81243 (Too much memory is allocated for preg_replace()). Standard: Fixed bug #81223 (flock() only locks first byte of file). Version 7.4.21 01 Jul 2021 Core: Fixed bug #81068 (Double free in realpath_cache_clean()). Fixed bug #76359 (open_basedir bypass through adding \"..\"). Fixed bug #81090 (Typed property performance degradation with .= operator). Fixed bug #81070 (Integer underflow in memory limit comparison). Fixed bug #81122 (SSRF bypass in FILTER_VALIDATE_URL). (CVE-2021-21705) Bzip2: Fixed bug #81092 (fflush before stream_filter_remove corrupts stream). OpenSSL: Fixed bug #76694 (native Windows cert verification uses CN as server name). PDO_Firebird: Fixed bug #76448 (Stack buffer overflow in firebird_info_cb). (CVE-2021-21704) Fixed bug #76449 (SIGSEGV in firebird_handle_doer). (CVE-2021-21704) Fixed bug #76450 (SIGSEGV in firebird_stmt_execute). (CVE-2021-21704) Fixed bug #76452 (Crash while parsing blob data in firebird_fetch_blob). (CVE-2021-21704) Standard: Fixed bug #81048 (phpinfo(INFO_VARIABLES) \"Array to string conversion\"). Version 7.4.20 03 Jun 2021 Core: Fixed bug #80929 (Method name corruption related to repeated calls to call_user_func_array). Fixed bug #80960 (opendir() warning wrong info when failed on Windows). Fixed bug #67792 (HTTP Authorization schemes are treated as case-sensitive). Fixed bug #80972 (Memory exhaustion on invalid string offset). FPM: Fixed bug #65800 (Events port mechanism). FTP: Fixed bug #80901 (Info leak in ftp extension). Fixed bug #79100 (Wrong FTP error messages). GD: Fixed bug #81032 (GD install is affected by external libgd installation). MBString: Fixed bug #81011 (mb_convert_encoding removes references from arrays). ODBC: Fixed bug #80460 (ODBC doesn\'t account for SQL_NO_TOTAL indicator). PDO_MySQL: Fixed bug #81037 (PDO discards error message text from prepared statement). PDO_ODBC: Fixed bug #44643 (bound parameters ignore explicit type definitions). pgsql: Fixed php_pgsql_fd_cast() wrt. php_stream_can_cast(). SPL: Fixed bug #80933 (SplFileObject::DROP_NEW_LINE is broken for NUL and CR). Opcache: Fixed bug #80900 (switch statement behavior inside function). Fixed bug #81015 (Opcache optimization assumes wrong part of ternary operator in if-condition). XMLReader: Fixed bug #73246 (XMLReader: encoding length not checked). Zip: Fixed bug #80863 (ZipArchive::extractTo() ignores references). Version 7.4.19 06 May 2021 PDO_pgsql: Reverted bug fix for #80892 (PDO::PARAM_INT is treated the same as PDO::PARAM_STR). Version 7.4.18 29 Apr 2021 Core: Fixed bug #80781 (Error handler that throws ErrorException infinite loop). Fixed bug #75776 (Flushing streams with compression filter is broken). Dba: Fixed bug #80817 (dba_popen() may cause segfault during RSHUTDOWN). DOM: Fixed bug #66783 (UAF when appending DOMDocument to element). FPM: Fixed bug #80024 (Duplication of info about inherited socket after pool removing). FTP: Fixed bug #80880 (SSL_read on shutdown, ftp/proc_open). Imap: Fixed bug #80710 (imap_mail_compose() header injection). Intl: Fixed bug #80763 (msgfmt_format() does not accept DateTime references). LibXML: Fixed bug #51903 (simplexml_load_file() doesn\'t use HTTP headers). Fixed bug #73533 (Invalid memory access in php_libxml_xmlCheckUTF8). MySQLnd: Fixed bug #80713 (SegFault when disabling ATTR_EMULATE_PREPARES and MySQL 8.0). Fixed bug #80837 (Calling stmt_store_result after fetch doesn\'t throw an error). Fixed bug #78680 (mysqlnd\'s mysql_clear_password does not transmit null-terminated password). Opcache: Fixed bug #80805 (create simple class and get error in opcache.so). Fixed bug #80950 (Variables become null in if statements). Pcntl: Fixed bug #79812 (Potential integer overflow in pcntl_exec()). PCRE: Fixed bug #80866 (preg_split ignores limit flag when pattern with \\K has 0-width fullstring match). PDO_ODBC: Fixed bug #80783 (PDO ODBC truncates BLOB records at every 256th byte). PDO_pgsql: Fixed bug #80892 (PDO::PARAM_INT is treated the same as PDO::PARAM_STR). phpdbg: Fixed bug #80757 (Exit code is 0 when could not open file). Session: Fixed bug #80774 (session_name() problem with backslash). Fixed bug #80889 (Cannot set save handler when save_handler is invalid). SOAP: Fixed bug #69668 (SOAP special XML characters in namespace URIs not encoded). Standard: Fixed bug #78719 (http wrapper silently ignores long Location headers). Fixed bug #80771 (phpinfo(INFO_CREDITS) displays nothing in CLI). Fixed bug #80838 (HTTP wrapper waits for HTTP 1 response after HTTP 101). Fixed bug #80915 (Taking a reference to $_SERVER hides its values from phpinfo()). Fixed bug #80654 (file_get_contents() maxlen fails above (2
*
*31)-1 bytes). MySQLi: Fixed bug #74779 (x() and y() truncating floats to integers). OPcache: Fixed bug #80682 (opcache doesn\'t honour pcre.jit option). OpenSSL: Fixed bug #80747 (Providing RSA key size < 512 generates key that crash PHP). Phar: Fixed bug #75850 (Unclear error message wrt. __halt_compiler() w/o semicolon) (cmb) Fixed bug #70091 (Phar does not mark UTF-8 filenames in ZIP archives). Fixed bug #53467 (Phar cannot compress large archives). SPL: Fixed bug #80719 (Iterating after failed ArrayObject::setIteratorClass() causes Segmentation fault). Zip: Fixed bug #80648 (Fix for bug 79296 should be based on runtime version). Version 7.4.16 04 Mar 2021 Core: Fixed bug #80706 (mail(): Headers after Bcc headers may be ignored). MySQLnd: Fixed bug #78680 (mysqlnd\'s mysql_clear_password does not transmit null-terminated password). MySQLi: Fixed bug #74779 (x() and y() truncating floats to integers). OPcache: Fixed bug #80682 (opcache doesn\'t honour pcre.jit option). OpenSSL: Fixed bug #80747 (Providing RSA key size < 512 generates key that crash PHP). Phar: Fixed bug #75850 (Unclear error message wrt. __halt_compiler() w/o semicolon) (cmb) Fixed bug #70091 (Phar does not mark UTF-8 filenames in ZIP archives). Fixed bug #53467 (Phar cannot compress large archives). SPL: Fixed bug #80719 (Iterating after failed ArrayObject::setIteratorClass() causes Segmentation fault). Standard: Fixed bug #80654 (file_get_contents() maxlen fails above (2
*
*31)-1 bytes). Zip: Fixed bug #80648 (Fix for bug 79296 should be based on runtime version). Version 7.4.15 04 Feb 2021 Core: Fixed bug #80523 (bogus parse error on >4GB source code). Fixed bug #80384 (filter buffers entire read until file closed). Curl: Fixed bug #80595 (Resetting POSTFIELDS to empty array breaks request). Date: Fixed bug #80376 (last day of the month causes runway cpu usage. MySQLi: Fixed bug #67983 (mysqlnd with MYSQLI_OPT_INT_AND_FLOAT_NATIVE fails to interpret bit columns). Fixed bug #64638 (Fetching resultsets from stored procedure with cursor fails). Fixed bug #72862 (segfault using prepared statements on stored procedures that use a cursor). Fixed bug #77935 (Crash in mysqlnd_fetch_stmt_row_cursor when calling an SP with a cursor). Phar: Fixed bug #77565 (Incorrect locator detection in ZIP-based phars). Fixed bug #69279 (Compressed ZIP Phar extractTo() creates garbage files). SOAP: Fixed bug #80672 (Null Dereference in SoapClient). (CVE-2021-21702) Version 7.4.14 07 Jan 2021 Core: Fixed bug #74558 (Can\'t rebind closure returned by Closure::fromCallable()). Fixed bug #80345 (PHPIZE configuration has outdated PHP_RELEASE_VERSION). Fixed bug #72964 (White space not unfolded for CC/Bcc headers). Fixed bug #80362 (Running dtrace scripts can cause php to crash). Fixed bug #80393 (Build of PHP extension fails due to configuration gap with libtool). Fixed bug #80402 (configure filtering out -lpthread). Fixed bug #77069 (stream filter loses final block of data). Fileinfo: Fixed bug #77961 (finfo_open crafted magic parsing SIGABRT). FPM: Fixed bug #69625 (FPM returns 200 status on request without SCRIPT_FILENAME env). Intl: Fixed bug #80425 (MessageFormatAdapter::getArgTypeList redefined). OpenSSL: Fixed bug #80368 (OpenSSL extension fails to build against LibreSSL due to lack of OCB support). Phar: Fixed bug #73809 (Phar Zip parse crash - mmap fail). Fixed bug #75102 (`PharData` says invalid checksum for valid tar). Fixed bug #77322 (PharData::addEmptyDir(\'/\') Possible integer overflow). PDO MySQL: Fixed bug #80458 (PDOStatement::fetchAll() throws for upsert queries). Fixed bug #63185 (nextRowset() ignores MySQL errors with native prepared statements). Fixed bug #78152 (PDO::exec() - Bad error handling with multiple commands). Fixed bug #70066 (Unexpected \"Cannot execute queries while other unbuffered queries\"). Fixed bug #71145 (Multiple statements in init command triggers unbuffered query error). Fixed bug #76815 (PDOStatement cannot be GCed/closeCursor-ed when a PROCEDURE resultset SIGNAL). Standard: Fixed bug #77423 (FILTER_VALIDATE_URL accepts URLs with invalid userinfo). (CVE-2020-7071) Fixed bug #80366 (Return Value of zend_fstat() not Checked). Fixed bug #80411 (References to null-serialized object break serialize()). Tidy: Fixed bug #77594 (ob_tidyhandler is never reset). Zlib: Fixed bug #48725 (Support for flushing in zlib stream). Version 7.4.13 26 Nov 2020 Core: Fixed bug #80280 (ADD_EXTENSION_DEP() fails for ext/standard and ext/date). Fixed bug #80258 (Windows Deduplication Enabled, randon permission errors). COM: Fixed bug #62474 (com_event_sink crashes on certain arguments). DOM: Fixed bug #80268 (loadHTML() truncates at NUL bytes). FFI: Fixed bug #79177 (FFI doesn\'t handle well PHP exceptions within callback). IMAP: Fixed bug #64076 (imap_sort() does not return FALSE on failure). Fixed bug #76618 (segfault on imap_reopen). Fixed bug #80239 (imap_rfc822_write_address() leaks memory). Fixed minor regression caused by fixing bug #80220. Fixed bug #80242 (imap_mail_compose() segfaults for multipart with rfc822). MySQLi: Fixed bug #79375 (mysqli_store_result does not report error from lock wait timeout). Fixed bug #76525 (mysqli::commit does not throw if MYSQLI_REPORT_ERROR enabled and mysqlnd used). Fixed bug #72413 (mysqlnd segfault (fetch_row second parameter typemismatch)). ODBC: Fixed bug #44618 (Fetching may rely on uninitialized data). Opcache: Fixed bug #79643 (PHP with Opcache crashes when a file with specific name is included). Fixed run-time binding of preloaded dynamically declared function. OpenSSL: Fixed bug #79983 (openssl_encrypt / openssl_decrypt fail with OCB mode). PDO MySQL: Fixed bug #66528 (No PDOException or errorCode if database becomes unavailable before PDO::commit). Fixed bug #65825 (PDOStatement::fetch() does not throw exception on broken server connection). SNMP: Fixed bug #70461 (disable md5 code when it is not supported in net-snmp). Standard: Fixed bug #80266 (parse_url silently drops port number 0). Version 7.4.12 29 Oct 2020 Core: Fixed bug #80061 (Copying large files may have suboptimal performance). Fixed bug #79423 (copy command is limited to size of file it can copy). Fixed bug #80126 (Covariant return types failing compilation). Fixed bug #80186 (Segfault when iterating over FFI object). Calendar: Fixed bug #80185 (jdtounix() fails after 2037). IMAP: Fixed bug #80213 (imap_mail_compose() segfaults on certain $bodies). Fixed bug #80215 (imap_mail_compose() may modify by-val parameters). Fixed bug #80220 (imap_mail_compose() may leak memory). Fixed bug #80223 (imap_mail_compose() leaks envelope on malformed bodies). Fixed bug #80216 (imap_mail_compose() does not validate types/encodings). Fixed bug #80226 (imap_sort() leaks sortpgm memory). MySQLnd: Fixed bug #80115 (mysqlnd.debug doesn\'t recognize absolute paths with slashes). Fixed bug #80107 (mysqli_query() fails for ~16 MB long query when compression is enabled). ODBC: Fixed bug #78470 (odbc_specialcolumns() no longer accepts $nullable). Fixed bug #80147 (BINARY strings may not be properly zero-terminated). Fixed bug #80150 (Failure to fetch error message). Fixed bug #80152 (odbc_execute() moves internal pointer of $params). Fixed bug #46050 (odbc_next_result corrupts prepared resource). OPcache: Fixed bug #80083 (Optimizer pass 6 removes variables used for ibm_db2 data binding). Fixed bug #80194 (Assertion failure during block assembly of unreachable free with leading nop). PCRE: Updated to PCRE 10.35. Fixed bug #80118 (Erroneous whitespace match with JIT only). PDO_ODBC: Fixed bug #67465 (NULL Pointer dereference in odbc_handle_preparer). Standard: Fixed bug #80114 (parse_url does not accept URLs with port 0). Fixed bug #76943 (Inconsistent stream_wrapper_restore() errors). Fixed bug #76735 (Incorrect message in fopen on invalid mode). Tidy: Fixed bug #77040 (tidyNode::isHtml() is completely broken). Version 7.4.11 01 Oct 2020 Core: Fixed bug #79699 (PHP parses encoded cookie names so malicious `__Host-` cookies can be sent). (CVE-2020-7070) Fixed bug #79979 (passing value to by-ref param via CUFA crashes). Fixed bug #80037 (Typed property must not be accessed before initialization when __get() declared). Fixed bug #80048 (Bug #69100 has not been fixed for Windows). Fixed bug #80049 (Memleak when coercing integers to string via variadic argument). Calendar: Fixed bug #80007 (Potential type confusion in unixtojd() parameter parsing). COM: Fixed bug #64130 (COM obj parameters passed by reference are not updated). OPcache: Fixed bug #80002 (calc free space for new interned string is wrong). Fixed bug #80046 (FREE for SWITCH_STRING optimized away). Fixed bug #79825 (opcache.file_cache causes SIGSEGV when custom opcode handlers changed). OpenSSL: Fixed bug #79601 (Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV). (CVE-2020-7069) PDO: Fixed bug #80027 (Terrible performance using $query->fetch on queries with many bind parameters). SOAP: Fixed bug #47021 (SoapClient stumbles over WSDL delivered with \"Transfer-Encoding: chunked\"). Standard: Fixed bug #79986 (str_ireplace bug with diacritics characters). Fixed bug #80077 (getmxrr test bug). Fixed bug #72941 (Modifying bucket->data by-ref has no effect any longer). Fixed bug #80067 (Omitting the port in bindto setting errors). Version 7.4.10 03 Sep 2020 Core: Fixed bug #79884 (PHP_CONFIG_FILE_PATH is meaningless). Fixed bug #77932 (File extensions are case-sensitive). Fixed bug #79806 (realpath() erroneously resolves link to link). Fixed bug #79895 (PHP_CHECK_GCC_ARG does not allow flags with equal sign). Fixed bug #79919 (Stack use-after-scope in define()). Fixed bug #79934 (CRLF-only line in heredoc causes parsing error). Fixed bug #79947 (Memory leak on invalid offset type in compound assignment). COM: Fixed bug #48585 (com_load_typelib holds reference, fails on second call). Exif: Fixed bug #75785 (Many errors from exif_read_data). Gettext: Fixed bug #70574 (Tests fail due to relying on Linux fallback behavior for gettext()). LDAP: Fixed memory leaks. OPcache: Fixed bug #73060 (php failed with error after temp folder cleaned up). Fixed bug #79917 (File cache segfault with a static variable in inherited method). PDO: Fixed bug #64705 (errorInfo property of PDOException is null when PDO::__construct() fails). Session: Fixed bug #79724 (Return type does not match in ext/session/mod_mm.c). Standard: Fixed bug #79930 (array_merge_recursive() crashes when called with array with single reference). Fixed bug #79944 (getmxrr always returns true on Alpine linux). Fixed bug #79951 (Memory leak in str_replace of empty string). XML: Fixed bug #79922 (Crash after multiple calls to xml_parser_free()). Version 7.4.9 06 Aug 2020 Apache: Fixed bug #79030 (Upgrade apache2handler\'s php_apache_sapi_get_request_time to return usec). COM: Fixed bug #63208 (BSTR to PHP string conversion not binary safe). Fixed bug #63527 (DCOM does not work with Username, Password parameter). Core: Fixed bug #79740 (serialize() and unserialize() methods can not be called statically). Fixed bug #79783 (Segfault in php_str_replace_common). Fixed bug #79778 (Assertion failure if dumping closure with unresolved static variable). Fixed bug #79779 (Assertion failure when assigning property of string offset by reference). Fixed bug #79792 (HT iterators not removed if empty array is destroyed). Fixed bug #78598 (Changing array during undef index RW error segfaults). Fixed bug #79784 (Use after free if changing array during undef var during array write fetch). Fixed bug #79793 (Use after free if string used in undefined index warning is changed). Fixed bug #79862 (Public non-static property in child should take priority over private static). Fixed bug #79877 (getimagesize function silently truncates after a null byte) (cmb) Fileinfo: Fixed bug #79756 (finfo_file crash (FILEINFO_MIME)). FTP: Fixed bug #55857 (ftp_size on large files). Mbstring: Fixed bug #79787 (mb_strimwidth does not trim string). Phar: Fixed bug #79797 (Use of freed hash key in the phar_parse_zipfile function). (CVE-2020-7068) Reflection: Fixed bug #79487 (::getStaticProperties() ignores property modifications). Fixed bug #69804 (::getStaticPropertyValue() throws on protected props). Fixed bug #79820 (Use after free when type duplicated into ReflectionProperty gets resolved). Standard: Fixed bug #70362 (Can\'t copy() large \'data://\' with open_basedir). Fixed bug #78008 (dns_check_record() always return true on Alpine). Fixed bug #79839 (array_walk() does not respect property types). Version 7.4.8 09 Jul 2020 Core: Fixed bug #79595 (zend_init_fpu() alters FPU precision). Fixed bug #79650 (php-win.exe 100% cpu lockup). Fixed bug #79668 (get_defined_functions(true) may miss functions). Fixed bug #79683 (Fake reflection scope affects __toString()). Fixed possibly unsupported timercmp() usage. Exif: Fixed bug #79687 (Sony picture - PHP Warning - Make, Model, MakerNotes). Fileinfo: Fixed bug #79681 (mime_content_type/finfo returning incorrect mimetype). Filter: Fixed bug #73527 (Invalid memory access in php_filter_strip). GD: Fixed bug #79676 (imagescale adds black border with IMG_BICUBIC). OpenSSL: Fixed bug #62890 (default_socket_timeout=-1 causes connection to timeout). PDO SQLite: Fixed bug #79664 (PDOStatement::getColumnMeta fails on empty result set). phpdbg: Fixed bug #73926 (phpdbg will not accept input on restart execution). Fixed bug #73927 (phpdbg fails with windows error prompt at \"watch array\"). Fixed several mostly Windows related phpdbg bugs. SPL: Fixed bug #79710 (Reproducible segfault in error_handler during GC involved an SplFileObject). Standard: Fixed bug #74267 (segfault with streams and invalid data). Version 7.4.7 11 Jun 2020 Core: Fixed bug #79599 (coredump in set_error_handler). Fixed bug #79566 (Private SHM is not private on Windows). Fixed bug #79489 (.user.ini does not inherit). Fixed bug #79600 (Regression in 7.4.6 when yielding an array based generator). Fixed bug #79657 (\"yield from\" hangs when invalid value encountered). FFI: Fixed bug #79571 (FFI: var_dumping unions may segfault). GD: Fixed bug #79615 (Wrong GIF header written in GD GIFEncode). MySQLnd: Fixed bug #79596 (MySQL FLOAT truncates to int some locales). Opcache: Fixed bug #79588 (Boolean opcache settings ignore on/off values). Fixed bug #79548 (Preloading segfault with inherited method using static variable). Fixed bug #79603 (RTD collision with opcache). Standard: Fixed bug #79561 (dns_get_record() fails with DNS_ALL).- fixes [bsc#1203867] and [bsc#1203870]- modified patches % php-no-build-date.patch (refreshed) % php7-arm-build-fixes.patch (refreshed)- deleted patches - php-fix_net-snmp_disable_MD5.patch (upstreamed) - php-odbc-cmp-int-cast.patch (not needed, dropped from factory as well, see last comment of https://bugs.php.net/bug.php?id=52554) - php7-CVE-2017-8923.patch (upstreamed) - php7-CVE-2020-7068.patch (upstreamed) - php7-CVE-2020-7069.patch (upstreamed) - php7-CVE-2020-7070.patch (upstreamed) - php7-CVE-2020-7071.patch (upstreamed) - php7-CVE-2021-21702.patch (upstreamed) - php7-CVE-2021-21703.patch (upstreamed) - php7-CVE-2021-21704.patch (upstreamed) - php7-CVE-2021-21705.patch (upstreamed) - php7-CVE-2021-21707.patch (upstreamed) - php7-CVE-2021-21708.patch (upstreamed) - php7-CVE-2022-31625.patch (upstreamed) - php7-CVE-2022-31626.patch (upstreamed)
* Mon Jun 20 2022 pgajdosAATTsuse.com- security update- added patches fix CVE-2022-31625 [bsc#1200645], uninitialized pointers free in Postgres extension + php7-CVE-2022-31625.patch
* Mon Jun 20 2022 pgajdosAATTsuse.com- security update- added patches fix CVE-2022-31626 [bsc#1200628], buffer overflow via user-supplied password when using pdo_mysql extension with mysqlnd driver + php7-CVE-2022-31626.patch
* Fri May 06 2022 pgajdosAATTsuse.com- security update [bsc#1197644]- added patches fix https://github.com/php/php-src/commit/771dbdb319fa7f90584f6b2cc2c54ccff570492d + php7-signedness-php_filter_validate_domain.patch
* Tue Feb 22 2022 pgajdosAATTsuse.com- security update- added patches fix CVE-2021-21708 [bsc#1196252], Use after free due to php_filter_float() failing for ints + php7-CVE-2021-21708.patch
* Mon Feb 14 2022 pgajdosAATTsuse.com- security update- added patches fix CVE-2017-8923 [bsc#1038980], denial of service (application crash) by using .= with a long string (zend_string_extend func in Zend/zend_string.h) + php7-CVE-2017-8923.patch
* Fri Nov 26 2021 pgajdosAATTsuse.com- security update- added patches fix CVE-2021-21707 [bsc#1193041], special character breaks path in xml parsing + php7-CVE-2021-21707.patch
* Fri Oct 29 2021 pgajdosAATTsuse.com- security update- added patches fix CVE-2021-21703 [bsc#1192050], Local privilege escalation via PHP-FPM + php7-CVE-2021-21703.patch
* Mon Oct 04 2021 pgajdosAATTsuse.com- added patches [bsc#1175508] fix https://github.com/php/php-src/pull/7428 + php7-bsc1175508.patch
* Mon Aug 02 2021 pgajdosAATTsuse.com- security update- added patches fix CVE-2021-21704 [bsc#1188035], security issues in pdo_firebase module + php7-CVE-2021-21704.patch
* Fri Jul 09 2021 pgajdosAATTsuse.com- security update- added patches fix CVE-2021-21705 [bsc#1188037], SSRF bypass in FILTER_VALIDATE_URL + php7-CVE-2021-21705.patch
* Thu Feb 11 2021 pgajdosAATTsuse.com- security update- added patches fix CVE-2021-21702 [bsc#1182049], NULL pointer dereference in SoapClient + php7-CVE-2021-21702.patch
* Mon Jan 11 2021 pgajdosAATTsuse.com- security update- added patches fix CVE-2020-7071 [bsc#1180706], FILTER_VALIDATE_URL accepts URLs with invalid userinfo + php7-CVE-2020-7071.patch
* Fri Oct 09 2020 pgajdosAATTsuse.com- security update- added patches fix CVE-2020-7069 [bsc#1177351], when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is used + php7-CVE-2020-7069.patch fix CVE-2020-7070 [bsc#1177352], Percent-encoded cookies can be used to overwrite existing prefixed cookie names + php7-CVE-2020-7070.patch
* Thu Aug 13 2020 pgajdosAATTsuse.com- security update- added patches fix CVE-2020-7068 [bsc#1175223], Use of freed hash key in the phar_parse_zipfile function + php7-CVE-2020-7068.patch
* Thu Jul 09 2020 pgajdosAATTsuse.com- Use /run/php-fpm instead of /run/php- modified sources % php-fpm.tmpfiles.d
* Thu Jul 09 2020 pgajdosAATTsuse.com- do not install %{_tmpfilesdir}, %{_tmpfilesdir}/php-fpm.conf in test favour
* Mon Jul 06 2020 daniel.molkentinAATTsuse.com- added tmpfiles.d for php-fpm to provide a base base for a socket (boo#1173786)
* Thu May 14 2020 suse+buildAATTde-korte.org- updated to 7.4.6: This is a security release which also contains several bug fixes. See https://www.php.net/ChangeLog-7.php#7.4.6
* Wed May 13 2020 pgajdosAATTsuse.com- added patches build fixes in SLE12 + php7-arm-build-fixes.patch
* Tue May 12 2020 pgajdosAATTsuse.com- added to SLE-12 [jsc#SLE-12474]
* Tue May 12 2020 pgajdosAATTsuse.com- spec file usable under SLE12 again and better prepared for phpM -> phpMN transition
* Mon May 11 2020 pgajdosAATTsuse.com- added to SLE-15-SP2 [jsc#SLE-12482], including fixes for: CVE-2020-7063 [bsc#1165289] CVE-2020-7062 [bsc#1165280] CVE-2019-11046, CVE-2019-11050, CVE-2019-11047, CVE-2019-11045
* Tue Apr 14 2020 suse+buildAATTde-korte.org- updated to 7.4.5: This is a security release which also contains several bug fixes. See https://www.php.net/ChangeLog-7.php#7.4.5
* Thu Apr 02 2020 pgajdosAATTsuse.com- remove Berkeley DB Database support [jsc#SLE-12210]
* Fri Mar 20 2020 pgajdosAATTsuse.com- build firebird extension in any case
* Tue Mar 17 2020 suse+buildAATTde-korte.org- updated to 7.4.4: This is a security release which also contains several bug fixes. See https://www.php.net/ChangeLog-7.php#7.4.4
* Thu Mar 12 2020 mliskaAATTsuse.cz- Enable LTO as it works now (boo#1133275).
* Wed Feb 19 2020 suse+buildAATTde-korte.org- updated to 7.4.3: This is a security release which also contains several bug fixes. See https://www.php.net/ChangeLog-7.php#7.4.3
* Mon Feb 10 2020 pgajdosAATTsuse.com- add %apache_rex_deps
* Thu Jan 23 2020 suse+buildAATTde-korte.org- updated to 7.4.2: This is a security release which also contains several bug fixes. See https://www.php.net/ChangeLog-7.php#7.4.2
* Wed Dec 18 2019 suse+buildAATTde-korte.org- updated to 7.4.1: This is a security release which also contains several bug fixes. See https://www.php.net/ChangeLog-7.php#7.4.1- deleted patches - php-fix-mysqlnd-compression-library.patch - php-fpm-service-fails-to-start.patch
* Tue Dec 10 2019 pgajdosAATTsuse.com- php7-devel requires glibc-devel, libxml2-devel, pcre2-devel again
* Thu Dec 05 2019 suse+buildAATTde-korte.org- relax systemd restrictions for FPM as they were too strict in some applications- change leftover Requires php7- to php-- remove external libraries from -devel subpackage- added patches + php-fpm-service-fails-to-start.patch
* Thu Nov 28 2019 suse+buildAATTde-korte.org- update to 7.4.0:
* Typed Properties
* Arrow Functions
* Limited Return Type Covariance and Argument Type Contravariance
* Unpacking Inside Arrays
* Numeric Literal Separator
* Weak References
* Allow Exceptions from __toString()
* Opcache Preloading
* The interbase and wddx extensions are removed and now available through PECL
* PEAR is now packaged separately in php7-pear source package (https://externals.io/message/103977)
* See https://www.php.net/ChangeLog-7.php#7.4.0 for a complete list of changes- deleted patches - php-suse-addons.tar.bz - php-systzdata-v18.patch- added patches + php-fix-mysqlnd-compression-library.patch + php-systzdata-v19.patch + mod_php7.conf- modified files/patches % php-no-build-date.patch % php-systemd-unit.patch % php7.keyring (use keys of the PHP-7.4 release managers) % php7.rpmlintrc
* Tue Nov 19 2019 pgajdosAATTsuse.com- added to SLE-15-SP2 [SLE-10860], fixes CVE-2019-11043 [bsc#1154999] CVE-2019-11041 [bsc#1146360] CVE-2019-11042 [bsc#1145095] CVE-2019-11039 [bsc#1138173] CVE-2019-11040 [bsc#1138172] CVE-2019-11036 [bsc#1134322] CVE-2019-11034 [bsc#1132838] CVE-2019-11035 [bsc#1132837] CVE-2019-9637 [bsc#1128892] CVE-2019-9675 [bsc#1128886] CVE-2019-9638 [bsc#1128889], CVE-2019-9639 [bsc#1128887] CVE-2019-9640 [bsc#1128883] CVE-2019-9024 [bsc#1126821] CVE-2019-9020 [bsc#1126711] CVE-2018-20783 [bsc#1127122] CVE-2019-9021 [bsc#1126713] CVE-2019-9022 [bsc#1126827] CVE-2019-9023 [bsc#1126823] CVE-2019-9641 [bsc#1128722] CVE-2018-19935 [bsc#1118832] CVE-2018-17082 [bsc#1108753] CVE-2018-1000222 [bsc#1105434] CVE-2018-14851 [bsc#1103659] CVE-2017-9120 [bsc#1103661] CVE-2018-12882 [bsc#1099098] [bsc#1151793]
* Tue Nov 12 2019 dimstarAATTopensuse.org- Do not add the generic provides to the php7-test package.
* Fri Oct 25 2019 pgajdosAATTsuse.com- version update to 7.3.11: This is a security release which also contains several bug fixes. See https://www.php.net/ChangeLog-7.php#7.3.11
* Fri Oct 04 2019 pgajdosAATTsuse.com- provide test results via multibuild :test- added sources + _multibuild
* Mon Sep 30 2019 pgajdosAATTsuse.com- remove pcre.jit=0 setting default as https://bugs.php.net/bug.php?id=77260 is solved on pcre2 side [bsc#1124446]- modified patches % php-ini.patch (amended)
* Sun Sep 29 2019 suse+buildAATTde-korte.org- updated to 7.3.10: This is a security release which also contains several bug fixes. See https://www.php.net/ChangeLog-7.php#7.3.10
* Sat Aug 31 2019 suse+buildAATTde-korte.org- updated to 7.3.9: This is a security release which also contains several bug fixes. See https://www.php.net/ChangeLog-7.php#7.3.9
* Sat Aug 03 2019 suse+buildAATTde-korte.org- updated to 7.3.8: This is a security release which also contains several bug fixes. See https://www.php.net/ChangeLog-7.php#7.3.8
* Thu Jul 04 2019 suse+buildAATTde-korte.org- updated to 7.3.7: This is a bug fix release. See https://www.php.net/ChangeLog-7.php#7.3.7
* Thu May 30 2019 suse+buildAATTde-korte.org- updated to 7.3.6: This is a security release which also contains several bug fixes. See https://www.php.net/ChangeLog-7.php#7.3.6
* Wed May 29 2019 pgajdosAATTsuse.com- check via apache-rex
* Fri May 24 2019 pgajdosAATTsuse.com- build for 42.3
* Thu May 02 2019 suse+buildAATTde-korte.org- updated to 7.3.5: This is a security release which also contains several bug fixes. See https://www.php.net/ChangeLog-7.php#7.3.5
* Wed Apr 24 2019 mliskaAATTsuse.cz- Disable LTO (boo#1133275).
* Thu Apr 04 2019 suse+buildAATTde-korte.org- updated to 7.3.4: This is a security release which also contains several bug fixes. See https://www.php.net/ChangeLog-7.php#7.3.4
* Fri Mar 15 2019 pgajdosAATTsuse.com- upstream bug #41631 is already fixed [bsc#1129032]- deleted sources - README.default_socket_timeout (not needed)
* Fri Mar 08 2019 pgajdosAATTsuse.com- updated to 7.3.3: This is a security release which also contains several bug fixes. See http://www.php.net/ChangeLog-7.php#7.3.3- deleted patches - php-systzdata-v17.patch (upstreamed)- added patches + php-systzdata-v18.patch (thanks to remirepo)
* Tue Mar 05 2019 pgajdosAATTsuse.com- asan_build: build ASAN included- debug_build: build more suitable for debugging
* Thu Feb 28 2019 tchvatalAATTsuse.com- Disable tests that do deadlock now with curl update, this is fixed in next release 7.3.3 thus reenable here when released
* Thu Feb 28 2019 pgajdosAATTsuse.com- rename php7-
*.patch to more general php-#1.patch why: this aligns with maintenance patch names, which are in changelogs comfortably copied over php72, php7, php5, php53; moreover, php$N prefix causes issues when package is renamed, e. g. php7 to php72- deleted patches - php7-crypt-tests.patch - php7-date-regenerate-lexers.patch - php7-embed.patch - php7-fix_net-snmp_disable_MD5.patch - php7-ini.patch - php7-no-build-date.patch - php7-odbc-cmp-int-cast.patch - php7-openssl.patch - php7-php-config.patch - php7-phpize.patch - php7-pts.patch - php7-systemd-unit.patch - php7-systzdata-v17.patch- added patches + php-crypt-tests.patch + php-date-regenerate-lexers.patch + php-embed.patch + php-fix_net-snmp_disable_MD5.patch + php-ini.patch + php-no-build-date.patch + php-odbc-cmp-int-cast.patch + php-openssl.patch + php-php-config.patch + php-phpize.patch + php-pts.patch + php-systemd-unit.patch + php-systzdata-v17.patch
* Mon Feb 25 2019 pgajdosAATTsuse.com- fix wrongly ported patch, using the one from remirepo (Thanks!) [bsc#1126449]- modified patches % php7-systzdata-v17.patch
* Wed Feb 13 2019 pgajdosAATTsuse.com- updated to version 7.3.2: This is a bugfix release, with several bug fixes included. See http://php.net/ChangeLog-7.php#7.3.2- php7-systzdata-v16.patch modified and renamed to php7-systzdata-v17.patch
* Thu Feb 07 2019 pgajdosAATTsuse.com- set pcre.jit=0 until https://bugs.php.net/bug.php?id=77260 is solved [bsc#1124446]
* Thu Jan 31 2019 suse+buildAATTde-korte.org- spec file cleanup
* add BuildRequires gpg2
* remove outdated README.SUSE-pear - Squirrelmail uses PDO instead of DB now by default
* remove outdated php7-depdb-path.patch - Horde packages no longer build so need to be fixed anyway- update php7.rpmlintrc to suppress warnings that aren\'t fixable and drown out other warnings
* Wed Jan 30 2019 suse+buildAATTde-korte.org- provide the version of PEAR, rather than the PHP version in php-pear
* Wed Jan 30 2019 suse+buildAATTde-korte.org- configure cache_dir, metadata_dir and sig_bin through PHP_PEAR_
* exports
* Tue Jan 29 2019 suse+buildAATTde-korte.org- remove install-pear-nozlib.phar (the bundled and tested version from the PHP sources is fresh enough for our purposes)- merge back php7-pear-Archive_Tar in php7-pear- rename cache_dir to pear and create it
* Tue Jan 22 2019 suse+buildAATTde-korte.org- fix php7.spec typos
* Tue Jan 22 2019 pgajdosAATTsuse.com- verify install-pear-nozlib.phar
* Tue Jan 22 2019 suse+buildAATTde-korte.org- update install-pear-nozlib.phar to version 1.10.10
* switch source to GitHub
* provides Archive_Tar 1.4.4 (fixes CVE-2018-1000888)
* Mon Jan 14 2019 pgajdosAATTsuse.com- update to 7.3.1: This is a security release which also contains several bug fixes. See http://php.net/ChangeLog-7.php- remove suhosin stuff
* Sun Dec 30 2018 crrodriguezAATTopensuse.org- Support LMDB in php7-dba, it is advisable to use it instead of bdb.
* Thu Dec 20 2018 crodriguezAATTowncloud.com- Update php7-pts.patch: open slave_pty using TIOCGPTPEER if available instead of the name returned by ptsname() so it is safe to use when interacting with namespaces.
* Thu Dec 20 2018 crodriguezAATTowncloud.com- update install-pear-nozlib.phar to its latest version, otherwise pecl stops working due to protocol switch http -> https
* Wed Dec 19 2018 mpluskalAATTsuse.com- Mark testresults package as noarch
* Thu Dec 13 2018 mpluskalAATTsuse.com- Enable testsuite during build time and save log to subpackage testresults (boo#1119396)
* Mon Dec 10 2018 crrodriguezAATTopensuse.org- update to pcre2 broke building third party modules, php7-devel needs pcre-devel --> pcre2-devel change.
* Mon Dec 10 2018 pgajdosAATTsuse.com- update to 7.3.0:
* Improved PHP GC
* Add net_get_interfaces()
* Implemented flexible heredoc and nowdoc syntax
* Added support for references in list() and array destructuring
* Added syslog.facility and syslog.ident INI entries for customizing syslog logging
* The declaration and use of case-insensitive constants has been deprecated
* Added syslog.filter INI entry for syslog filtering
* Added the \'add_slashes\' sanitization mode
* Added support for WebP in imagecreatefromstring()
* Export internal structures and accessor helpers for GMP object.
* Added gmp_binomial(n, k)
* Added gmp_lcm(a, b)
* Added gmp_perfect_power(a)
* Added gmp_kronecker(a, b)
* Added JSON_THROW_ON_ERROR flag
* Added ldap_exop_refresh helper for EXOP REFRESH operation with dds overlay
* Added full support for sending and parsing ldap controls
* Removed support for ODBCRouter
* Removed support for Birdstep
* Added openssl_pkey_derive function
* Add min_proto_version and max_proto_version ssl stream options as well as related constants for possible TLS protocol values
* Migrated to PCRE2
* Expose TDS version as \\PDO::DBLIB_ATTR_TDS_VERSION attribute on \\PDO instance
* Treat DATETIME2 columns like DATETIME
* Added is_countable() function
* Added support for the SameSite cookie directive, including an alternative signature for setcookie(), setrawcookie() and session_set_cookie_params()
* Many bugfixes and other changes, see http://php.net/ChangeLog-7.php#7.3.0- patch changes % php7-ini.patch % php7-no-build-date.patch % php7-odbc-cmp-int-cast.patch - php7-honor-re2c-flags.patch (upstreamed)
* Mon Dec 10 2018 pgajdosAATTsuse.com- update to 7.2.13: This is a security release. http://php.net/ChangeLog-7.php
* Fri Nov 16 2018 pgajdosAATTsuse.com- core package recommends instead of requires smtp_daemon [bsc#1115213]
* Fri Nov 09 2018 pgajdosAATTsuse.com- update to 7.2.12: This is a bugfix release. http://php.net/ChangeLog-7.php- forward ported: % php7-crypt-tests.patch % php7-honor-re2c-flags.patch % php7-odbc-cmp-int-cast.patch
* Mon Oct 15 2018 pgajdosAATTsuse.com- update to 7.2.11: This is a bugfix release. http://php.net/ChangeLog-7.php
* Mon Sep 17 2018 pgajdosAATTsuse.com- updated to 7.2.10: This is a security release which also contains several minor bug fixes. http://php.net/ChangeLog-7.php
* Mon Sep 17 2018 pgajdosAATTsuse.com- reenable php7-dba support of Berkeley DB [bsc#1108554]
* Tue Sep 11 2018 pgajdosAATTsuse.com- remove Supplements: packageand(%{apache_mmn}:%{name}) from Apache httpd module as I do not see the reason why system that have php7 and apache2 installed should get the module automatically as well. This had a drawback of selecting apache2-prefork while [#] zypper in apache2-worker The following 5 NEW packages are going to be installed: apache2 apache2-mod_php7 apache2-prefork apache2-utils apache2-worker [#] because apache2-mod_php7 Requires: apache2-prefork.
* Fri Aug 17 2018 pgajdosAATTsuse.com- updated to 7.2.9: This is a bugfix release. http://php.net/ChangeLog-7.php
* Fri Aug 03 2018 pgajdosAATTsuse.com- updated to 7.2.8: This is a security release which also contains several minor bug fixes. http://php.net/ChangeLog-7.php#7.2.8
* Tue Jun 26 2018 pgajdosAATTsuse.com- updated to 7.2.7: A Bugfix release which includes a segfault fix for opcache. http://php.net/ChangeLog-7.php#7.2.7
* Thu Jun 07 2018 pgajdosAATTsuse.com- actually build against system gd for 42.3, made a bold comment [bsc#1074025c#5]
* Tue May 29 2018 pgajdosAATTsuse.com- fix build for SLE12, where %license does not exist
* Tue May 29 2018 pgajdosAATTsuse.com- updated to 7.2.6: Bugfix release which includes a memory corruption fix for EXIF. http://php.net/ChangeLog-7.php#7.2.6
* Fri May 25 2018 idonmezAATTsuse.com- Remove php7-freetype-pkgconfig.patch as it seems to break Freetype detection on some systems bsc#1094534
* Tue May 15 2018 pgajdosAATTsuse.com- main package requires wwwrun:www user [bsc#1093025]
* Thu May 10 2018 pgajdosAATTsuse.com- better workaround for [bsc#1089487]: build mod_phpN.so instead of libphpN.so
* Wed May 09 2018 pgajdosAATTsuse.com- rename freetype-pkgconfig.patch to php7-freetype-pkgconfig.patch to align with the rest of patch names
* Mon May 07 2018 idonmezAATTsuse.com- Add freetype-pkgconfig.patch to fix build with new Freetype: use pkg-config to find Freetype libraries
* Mon Apr 30 2018 pgajdosAATTsuse.com- updated to 7.2.5: This is a security release which also contains several minor bug fixes. http://php.net/ChangeLog-7.php#7.2.5
* Thu Apr 19 2018 pgajdosAATTsuse.com- build-test.sh: generic spec file name
* Mon Apr 16 2018 pgajdosAATTsuse.com- apache2-mod_php7 does not provide libphp7.so [bsc#1089487]
* Wed Apr 04 2018 pgajdosAATTsuse.com- updated to 7.2.4: This is a security release with also contains several minor bug fixes. http://php.net/ChangeLog-7.php#7.2.4- php7-no-build-date.patch refreshed
* Mon Mar 26 2018 pgajdosAATTsuse.com- build firebird extension only for openSUSE (sle15 requirement)
* Tue Mar 20 2018 guillaume.gardetAATTopensuse.org- Fix build for %arm and aarch64
* Fri Mar 16 2018 pgajdosAATTsuse.com- drop imap extension [bsc#1084461]
* Sat Mar 10 2018 dimstarAATTopensuse.org- BuildRequire pkgconfig(enchant) instead of enchant-devel: enchant is moving to version 2.2, with an enchant-1 as compatibility package. By using the pkgconfig symbol, we don\'t have to care for the actual package name.
* Fri Mar 09 2018 pgajdosAATTsuse.com- updated to 7.2.3: This is a security release with also contains several minor bug fixes. http://php.net/ChangeLog-7.php#7.2.3- removed upstreamed php7-pgsql-memory-leak.patch- php7-systzdata-v15.patch refreshed and renamed to php7-systzdata-v16.patch
* Thu Feb 22 2018 crrodriguezAATTopensuse.org- php7-honor-re2c-flags.patch: honor RE2C_FLAGS everywhere.- remove generated lexers so they are recreated at build time
* Thu Feb 22 2018 crrodriguezAATTopensuse.org- php7-date-regenerate-lexers.patch: honor RE2C_FLAGS
* Thu Feb 22 2018 crrodriguezAATTopensuse.org- Support password_hash(\"...\", PASSWORD_ARGON2I), buildrequire libargon2 in supported products.
* Mon Feb 19 2018 crrodriguezAATTopensuse.org- Remove buildRequires on:
* libevent-devel: php7-fpm does not use it.
* pam-devel: not used- Add buildrequire on zlib-devel explicitly.- libvpx is not needed but libwebp is, only when not building against system gd. xft likewise.
* Mon Feb 19 2018 pgajdosAATTsuse.com- fixed memory leak in pgsql extension, php function pg_escape_bytea https://bugs.php.net/bug.php?id=75838 [bsc#1076970] (internal) + php7-pgsql-memory-leak.patch
* Wed Feb 07 2018 pgajdosAATTsuse.com- updated to 7.2.2: This is a bugfix release, with several bug fixes included. http://php.net/ChangeLog-7.php#7.2.2
* Fri Jan 26 2018 pgajdosAATTsuse.com- do not build against system gd when suse_version < 1500
* Tue Jan 23 2018 pgajdosAATTsuse.com- fix build for SLE12
*
* Tue Jan 09 2018 pgajdosAATTsuse.com- updated to 7.2.1: Several security bugs were fixed in this release. http://php.net/ChangeLog-7.php#7.2.1
* Tue Jan 02 2018 pgajdosAATTsuse.com- build against newer webp [bsc#1074121]
* Fri Dec 15 2017 pgajdosAATTsuse.com- build with SLE12
*
* Mon Dec 11 2017 pgajdosAATTsuse.com- updated to 7.2.0: features and improvements:
* Convert numeric keys in object/array casts
* Counting of non-countable objects
* Object typehint
* HashContext as Object
* Argon2 in password hash
* Improve TLS constants to sane values
* Mcrypt extension removed
* New sodium extension- patches: . php7-systzdata-v14.patch transformed to php7-systzdata-v15.patch . removed upstreamed php7-aarch64-mult.patch
* Mon Nov 27 2017 pgajdosAATTsuse.com- updated to 7.1.12: This is a bugfix release, with several bug fixes included.
* Wed Nov 01 2017 bluemer.markAATTgmail.com- Add php-cli as provides to php7
* Fri Oct 27 2017 pgajdosAATTsuse.com- updated to 7.1.11: This is a bugfix release, with several bug fixes included.
* Wed Oct 04 2017 pgajdosAATTsuse.com- fixed installation of wrong cli [bsc#1061555]
* Sat Sep 30 2017 jengelhAATTinai.de- Update not-so-useful repeated package summaries. Update the descriptions to have a bit more explanation. Replace old tar syntax.
* Wed Sep 27 2017 pgajdosAATTsuse.com- build and ship embed SAPI + php7-embed.patch
* Wed Sep 27 2017 pgajdosAATTsuse.com- updated to 7.1.10: Several bugs have been fixed, see https://secure.php.net/ChangeLog-7.php for details
* Tue Sep 12 2017 pgajdosAATTsuse.com- aarch64-mult.patch renamed to php7-aarch64-mult.patch
* Mon Sep 04 2017 pgajdosAATTsuse.com- php7-devel requires php7-pear [bsc#1057104]
* Fri Sep 01 2017 jweberhoferAATTweberhofer.at- Changes related to boo#1056822- New packaging macros in macros.php: %php_pearxmldir, %pear_phpdir, %pear_phpdir, %pear_testdir, %pear_datadir, %pear_cfgdir, %pear_wwwdir, %pear_metadir, %pecl_phpdir, %pecl_docdir, %pecl_testdir, %pecl_datadir- Updated packaging documentation in README.macros
* Thu Aug 31 2017 ilyaAATTilya.pp.ua- Updated to 7.1.9: Several bugs have been fixed.
* ChangeLog https://secure.php.net/ChangeLog-7.php#7.1.9
* Mon Aug 14 2017 pgajdosAATTsuse.com- added /usr/bin/php7 [bsc#734176]
* Mon Aug 07 2017 jweberhoferAATTweberhofer.at- php7-pear should explicitly require php7-pear-Archive_Tar otherwise this dependency must be declared in every php7-pear-
* package explicitly. [bnc#1052389]
* Wed Aug 02 2017 ilyaAATTilya.pp.ua- Updated to 7.1.8: Several bugs have been fixed.
* ChangeLog https://secure.php.net/ChangeLog-7.php#7.1.8
* Wed Jul 26 2017 ilyaAATTilya.pp.ua- Replace %__-type macro indirections.
* Fri Jul 21 2017 pgajdosAATTsuse.com- date extension: regenerate lexers when needed + php7-date-regenerate-lexers.patch
* Mon Jul 17 2017 pgajdosAATTsuse.com- dropped mcrypt extension [fate#323673]
* Mon Jul 17 2017 pgajdosAATTsuse.com- updated to 7.1.7: This is a security release with several bug fixes included.
* Mon Jul 03 2017 tchvatalAATTsuse.com- Drop sle11 support as we are not building against it anymore- Remove php7-BNC-457056.patch that was applied on sle11 only- Remove dependency on imap-devel, it is not used- Switch spell from aspell to enchant, dropping pspell subpackage- Remove unknown switch options from php cli build- Drop support for berkleydb format, by default there are more supported solutions built in php- Use %configure macro in the build phases
* Fri Jun 09 2017 pgajdosAATTsuse.com- updated to 7.1.6: Several bugs have been fixed.
* Fri May 12 2017 13ilyaAATTgmail.com- Updated to 7.1.5: Several bugs have been fixed.
* ChangeLog https://secure.php.net/ChangeLog-7.php#7.1.5
* Sat Apr 15 2017 13ilyaAATTgmail.com- Updated to 7.1.4: Several bugs have been fixed.
* ChangeLog https://secure.php.net/ChangeLog-7.php#7.1.4
* Fri Mar 17 2017 13ilyaAATTgmail.com- Updated to 7.1.3: Several bugs have been fixed.
* ChangeLog https://secure.php.net/ChangeLog-7.php#7.1.3
* Fri Mar 17 2017 kukukAATTsuse.com- Don\'t install the init script if we use systemd
* Mon Feb 20 2017 pgajdosAATTsuse.com- updated to 7.1.2: Several bugs have been fixed.- deleted php7-getrandom-test.patch, upstreamed
* Tue Feb 14 2017 pgajdosAATTsuse.com- updated to 7.1.1: This release is the first point release in the 7.x series. PHP 7.1 comes with numerous improvements and new features such as
* Nullable types
* Void return type
* Iterable pseudo-type
* Class constant visiblity modifiers
* Square bracket syntax for list() and the ability to specify keys in list()
* Catching multiple exceptions types
* Many more features and changes…- migration: http://php.net/manual/en/migration71.php- php7-systzdata-v13.patch replaced by php7-systzdata-v14.patch
* Thu Feb 02 2017 pgajdosAATTsuse.com- suggest php7-
* instead of php-
* [bsc#1022158c#4]- do not suggest php-suhosin at all as we do not build it (not ported to php7 yet)
* Tue Jan 24 2017 pgajdosAATTsuse.com- updated to 7.0.15: Several security bugs were fixed in this release.
* Mon Dec 12 2016 fbuiAATTsuse.com- Replace pkgconfig(libsystemd-
*) with pkgconfig(libsystemd) Nowadays pkgconfig(libsystemd) replaces all libsystemd-
* libs, which are obsolete.
* Mon Dec 12 2016 pgajdosAATTsuse.com- updated to 7.0.14: Several security bugs were fixed in this release.
* Fri Nov 11 2016 pgajdosAATTsuse.com- updated to 7.0.13: This is a security release. Several security bugs were fixed in this release.
* Mon Oct 24 2016 pgajdosAATTsuse.com- adjust firebird dependency
* Mon Oct 17 2016 pgajdosAATTsuse.com- updated to 7.0.12: This is a security release. Several security bugs were fixed in this release.
* Thu Sep 15 2016 pgajdosAATTsuse.com- updated to 7.0.11: Several security bugs were fixed in this release.
* Wed Aug 31 2016 crrodriguezAATTopensuse.org- php7-getrandom-test.patch: Fix incorrect test for the getrandom syscall.
* Mon Aug 22 2016 pgajdosAATTsuse.com- updated to 7.0.10: Several security bugs were fixed in this release.
* Mon Aug 01 2016 pgajdosAATTsuse.com- updated to 7.0.9: Several security bugs were fixed in this release, including the HTTP_PROXY issue.
* Thu Jun 23 2016 pgajdosAATTsuse.com- updated to 7.0.8: This is a security release. Several security bugs were fixed in this release.- removed: php7-mbstring-missing-return.patch (upstreamed)
* Mon Jun 20 2016 pgajdosAATTsuse.com- systemd unit: remove syslog.target from After [bsc#983938]
* Mon May 30 2016 pgajdosAATTsuse.com- updated to 7.0.7: This is a security release. Several security bugs were fixed in this release.
* Thu Apr 28 2016 pgajdosAATTsuse.com- updated to 7.0.6: This is a security release. Several security bugs were fixed in this release.
* removed upstreamed php7-no-reentrant-crypt.patch
* Mon Apr 25 2016 schwabAATTlinux-m68k.org- aarch64-mult.patch: fix asm constraints in aarch64 multiply macro
* Thu Apr 07 2016 pgajdosAATTsuse.com- build for sle12
* Wed Apr 06 2016 pgajdosAATTsuse.com- correct public key
* Fri Apr 01 2016 pgajdosAATTsuse.com- updated to 7.0.5
* Tue Mar 29 2016 pgajdosAATTsuse.com- firebird builds now
* Thu Mar 03 2016 jimmyAATTboombatower.com- update to 7.0.4
* Wed Feb 10 2016 pgajdosAATTsuse.com- updated to 7.0.3
* Thu Feb 04 2016 pgajdosAATTsuse.com- require postgresql-devel < 9.4 for sle12 to fix build
* Fri Jan 29 2016 pgajdosAATTsuse.com- more versioned provides
* Fri Jan 08 2016 pgajdosAATTsuse.com- update to 7.0.2: 31 reported bugs has been fixed, including 6 security related issues.
* Mon Dec 21 2015 jimmyAATTboombatower.com- update to 7.0.1
* Mon Dec 14 2015 pgajdosAATTsuse.com- php5-pear-Archive_Tar provides 1.4.0- install .depdb and .depdblock files along metadata
* php5-depdb-path.patch- versioned provides in subpackages
* Mon Dec 14 2015 jimmyAATTboombatower.com- Provide obsoletes for sub-packages to improve upgrade process.
* Wed Dec 09 2015 jimmyAATTboombatower.com- Obsolete php5 since php7 conflicts and should replace.
* Mon Dec 07 2015 pgajdosAATTsuse.com- marcello at ceschia.de: fix path php-fpm.conf
* Mon Nov 23 2015 pgajdosAATTsuse.com- set pear\'s metadata dir to %{peardir}
* Mon Nov 16 2015 ajAATTajaissle.de- Spec cleanup
* Split Archive_Tar from -pear sub packge to allow updating this part via rpm
* Added \"Provides: php-firebird\" to -firebird sub package
* Added \"Provides: mod_php_any\" to server api module packages - fastcgi and -fpm
* Mon Nov 16 2015 pgajdosAATTsuse.com- test mod_php with %apache_test_module_curl- restart apache during mod_php upgrade
* Tue Sep 08 2015 pgajdosAATTsuse.com- add php5-fix_net-snmp_disable_MD5.patch [bnc#944302]
* Fri Sep 04 2015 pgajdosAATTsuse.com- fixed segfault in odbc extension when result set is containing NULL (php bugs #52554, #53007) [bnc#935074] (internal) + php7-odbc-cmp-int-cast.patch
* Tue Jul 14 2015 pgajdosAATTsuse.com- updated to 7.0.0
* see NEWS for changes
* see UPGRADING for 5.6.x -> 7.0.x transition- removed unneded or not upstreamed patches for long time:
* php5-cloexec.patch
* php5-missing-extdeps.patch
* php5-format-string-issues.patch
* php5-per-mod-log.patch
* php5-apache24-updates.patch
* php5-crypto-checks.patch
* php5-systzdata-r12.patch (new: php7-systzdata-v13.patch)
* Mon Jul 13 2015 pgajdosAATTsuse.com- updated to 5.6.11: Five security-related issues in PHP were fixed in this release, including CVE-2015-3152.
* Thu Jun 25 2015 crrodriguezAATTopensuse.org- php5-systemd-unit.patch: set Killmode=mixed in order to ensure fpm and children forked by script can terminate cleanly.
* Wed Jun 24 2015 pgajdosAATTsuse.com- mod_php5.so executable
* Thu Jun 18 2015 pgajdosAATTsuse.com- use apache-rpm-macros
* Thu Jun 18 2015 pgajdosAATTsuse.com- updated to 5.6.10: Several bugs have been fixed as well as several security issues into some bundled libraries (CVE-2015-3414, CVE-2015-3415, CVE-2015-3416, CVE-2015-2325 and CVE-2015-2326).
* Fri Jun 05 2015 mrueckertAATTsuse.de- enable apparmor support: new BR libapparmor-devel
* Mon May 18 2015 pgajdosAATTsuse.com- update to 5.6.9: Several bugs have been fixed.- systzdata patch updated to r12 - php5-systzdata-r10.patch + php5-systzdata-r12.patch
* Fri Apr 24 2015 pgajdosAATTsuse.com- update to 5.6.8: Several bugs have been fixed some of them beeing security related, like CVE-2015-1351 and CVE-2015-1352.- refreshed php5-crypto-checks.patch
* Mon Apr 20 2015 pgajdosAATTsuse.com- configure php-fpm with --localstatedir=/var [bnc#927147]
* Wed Apr 08 2015 pgajdosAATTsuse.com- systzdata patch updated to r10 - php5-systzdata-v7.patch + php5-systzdata-r10.patch
* Thu Apr 02 2015 pgajdosAATTsuse.com- build against system gd and libzip only for 13.2 and above
* Tue Mar 24 2015 pgajdosAATTsuse.com- update to 5.6.7: Several bugs have been fixed as well as CVE-2015-0231, CVE-2015-2305 and CVE-2015-2331.
* Tue Mar 24 2015 pgajdosAATTsuse.com- build against system gd [bnc#923946]
* Fri Mar 20 2015 pgajdosAATTsuse.com- build against system libzip [bnc#922894]
* Mon Feb 23 2015 pgajdosAATTsuse.com- update to 5.6.6: fixes several bugs and addresses CVE-2015-0235 and CVE-2015-0273.
* Mon Feb 09 2015 pgajdosAATTsuse.com- added README.default_socket_timeout [bnc#907519]
* Tue Feb 03 2015 pgajdosAATTsuse.com- fix sle_11_sp3 build
* Mon Jan 26 2015 pgajdosAATTsuse.com- update to 5.6.5: This release fixes several bugs as well as CVE-2015-0231, CVE-2014-9427 and CVE-2015-0232.- removed patches:
* php-CVE-2014-9426.patch
* php-CVE-2014-9427.patch
* php-CVE-2015-0231.patch
* Wed Jan 21 2015 pgajdosAATTsuse.com- added php-CVE-2015-0231.patch [bnc#910659]
* Mon Jan 05 2015 pgajdosAATTsuse.com- added php-CVE-2014-9426.patch [bnc#911663]- added php-CVE-2014-9427.patch [bnc#911664]
* Fri Dec 19 2014 pgajdosAATTsuse.com- update to 5.6.4: This release fixes several bugs and one CVE related to unserialization.
* Tue Nov 18 2014 pgajdosAATTsuse.com- update to 5.6.3: This release fixes several bugs and one CVE in the fileinfo extension.
* Mon Oct 27 2014 pgajdosAATTsuse.com- update to 5.6.2: Four security-related bugs were fixed in this release, including fixes for CVE-2014-3668, CVE-2014-3669 and CVE-2014-3670.
* Tue Oct 14 2014 pgajdosAATTsuse.com- upgraded to 5.6.1:
* Several bugs were fixed in this release (including CVE-2014-3622).
 
ICM