Home » Releases » 5.6 » 5.6.40 »

PHP 5.6.13

PHP 5.6 is no longer officially supported by the PHP project.

Official support refers to that provided direct by the PHP Project.

If you install PHP via third-party packages, support timelines may be different. Please read the Release Support Policy for more information.

The latest release of PHP 5.6 is 5.6.40.

Source Code

Change Log

  • core

    • Fixed bug #69900 (Too long timeout on pipes).
      Anatol
    • Fixed bug #69487 (SAPI may truncate POST data).
      cmb
    • Fixed bug #70198 (Checking liveness does not work as expected).
      Shafreeck Sea
      Anatol Belski
    • Fixed bug #70172 (Use After Free Vulnerability in unserialize()). (CVE-2015-6834)
      Stas
    • Fixed bug #70219 (Use after free vulnerability in session deserializer). (CVE-2015-6835)
      taoguangchen at icloud dot com
  • cli server

    • Fixed bug #66606 (Sets HTTP_CONTENT_TYPE but not CONTENT_TYPE).
      wusuopu
      cmb
    • Fixed bug #70264 (CLI server directory traversal).
      cmb
  • date

    • Fixed bug #70266 (DateInterval::__construct.interval_spec is not supposed to be optional).
      cmb
    • Fixed bug #70277 (new DateTimeZone($foo) is ignoring text after null byte).
      cmb
  • exif

    • Fixed bug #70385 (Buffer over-read in exif_read_data with TIFF IFD tag byte value of 32 bytes).
      Stas
  • gmp

    • Fixed bug #70284 (Use after free vulnerability in unserialize() with GMP).
      stas
  • hash

    • Fixed bug #70312 (HAVAL gives wrong hashes in specific cases).
      letsgolee at naver dot com
  • mcrypt

    • Fixed bug #69833 (mcrypt fd caching not working).
      Anatol
  • opcache

    • Fixed bug #70237 (Empty while and do-while segmentation fault with opcode on CLI enabled).
      Dmitry
      Laruence
  • pcre

    • Fixed bug #70232 (Incorrect bump-along behavior with \K and empty string match).
      cmb
    • Fixed bug #70345 (Multiple vulnerabilities related to PCRE functions).
      Anatol Belski
  • soap

    • Fixed bug #70388 (SOAP serialize_function_call() type confusion / RCE). (CVE-2015-6836)
      Stas
  • spl

    • Fixed bug #70290 (Null pointer deref (segfault) in spl_autoload via ob_start).
      hugh at allthethings dot co dot nz
    • Fixed bug #70303 (Incorrect constructor reflection for ArrayObject).
      cmb
    • Fixed bug #70365 (Use-after-free vulnerability in unserialize() with SplObjectStorage). (CVE-2015-6834)
      taoguangchen at icloud dot com
    • Fixed bug #70366 (Use-after-free vulnerability in unserialize() with SplDoublyLinkedList). (CVE-2015-6834)
      taoguangchen at icloud dot com
  • standard

    • Fixed bug #70052 (getimagesize() fails for very large and very small WBMP).
      cmb
    • Fixed bug #70157 (parse_ini_string() segmentation fault with INI_SCANNER_TYPED).
      Tjerk
  • xslt

    • Fixed bug #69782 (NULL pointer dereference).
      CVE-2015-6837
      CVE-2015-6838) (Stas
  • zip

    • Fixed bug #70350 (ZipArchive::extractTo allows for directory traversal when creating directories). (CVE-2014-9767)
      neal at fb dot com

PHP 5.6


  Represents a security release