EXIF: Fixed bug #72926 (Uninitialized Thumbail Data Leads To Memory Leakage in exif_process_IFD_in_TIFF). Fixed bug #68976 (Use After Free Vulnerability in unserialize()). (CVE-2015-2787) Fixed bug #69134 (Per Directory Values overrides PHP_INI_SYSTEM configuration options). Why Is Email Failing? Ereg: Fixed bug #68740 (NULL Pointer Dereference).

Sqlite3: Fixed bug #68760 (SQLITE segfaults if custom collator throws an exception). Fixed bug #69121 (Segfault in get_current_user when script owner is not in passwd with ZTS build). Fixed bug #69474 (ODBC: Query with same field name from two tables returns incorrect result). The code is failing here.

Fixed bug #60022 ("use statement [...] has no effect" depends on leading backslash). PCRE: Fixed bug #72688 (preg_match missing group names in matches). Fixed bug #68731 (finfo_buffer doesn't extract the correct mime with some gifs). Fileinfo: Fixed bug #68819 (Fileinfo on specific file causes spurious OOM and/or segfault). (CVE-2015-4604, CVE-2015-4605) GD: Fixed bug #68601 (buffer read overflow in gd_gif_in.c). (CVE-2014-9709) Phar: Fixed bug #68901 (use after

Fixed bug #71039 (exec functions ignore length but look for NULL termination). Fixed bug #73052 (Memory Corruption in During Deserialized-object Destruction). (CVE-2016-7411) Streams: Fixed bug #72853 (stream_set_blocking doesn't work).

Phar: Fixed bug #69958 (Segfault in Phar::convertToData on invalid file). (CVE-2015-5589) Fixed bug #69923 (Buffer overflow and stack smashing error in phar_fix_filepath). (CVE-2015-5590) SimpleXML: Refactored the fix for bug #66084 (simplexml_load_string() Fixed bug #72703 (Out of bounds global memory read in BF_crypt triggered by password_verify). hash: Fixed bug #70312 (HAVAL gives wrong hashes in specific cases).

Fixed bug #72910 (Out of bounds heap read in mbc_to_code() / triggered by mb_ereg_match()). Fixed bug #72114 (Integer underflow / arbitrary null write in fread/gzread). (CVE-2016-5096) Fixed bug #72135 (Integer Overflow in php_html_entities). (CVE-2016-5094) GD: Fixed bug #72227 (imagescale out-of-bounds read). (CVE-2013-7456) Intl: Fixed bug CLI: Fixed bug #67741 (auto_prepend_file messes up __LINE__).

Fixed bug #70157 (parse_ini_string() segmentation fault with INI_SCANNER_TYPED). Fixed bug #69141 (Missing arguments in reflection info for some builtin functions). Standard: Fixed bug #71840 (Unserialize accepts wrongly data). Mysqlnd: Fixed bug #72293 (Heap overflow in mysqlnd related to BIT fields). (CVE-2016-7412) PDO: Fixed bug #60665 (call to empty() on NULL result using PDO::FETCH_LAZY returns false).

Intl: Fixed bug #73218 (add mitigation for ICU int overflow). in /home/php.com/browscap/browscap/Browscap.php on line 596 Warning: fsockopen() [function.fsockopen]: php_network_getaddresses: getaddrinfo failed: Этот хост неизвестен. Fixed bug #69139 (Crash in gc_zval_possible_root on unserialize). Fixed bug #68677 (Use After Free). (CVE-2015-1351) OpenSSL: Fixed bug #67403 (Add signatureType to openssl_x509_parse).

Remote Fixed bug #72496 (Cannot declare public method with signature incompatible with parent private method). Version 5.5.36 26 May 2016 Core: Fixed bug #72114 (Integer underflow / arbitrary null write in fread/gzread). (CVE-2016-5096) Fixed bug #72135 (Integer Overflow in php_html_entities). (CVE-2016-5094) GD: Fixed bug #72227 (imagescale

Fixed bug #64931 (phar_add_file is too restrictive on filename). Calendar: Fixed bug #67976 (cal_days_month() fails for final month of the French calendar). Fixed bug #69038 (switch(SOMECONSTANT) misbehaves). PCRE: Fixed bug #70232 (Incorrect bump-along behavior with \K and empty string match).

Postgres: Fixed bug #69667 (segfault in php_pgsql_meta_data). (CVE-2015-4644) Sqlite3: Upgrade bundled sqlite to (CVE-2015-3414, CVE-2015-3415, CVE-2015-3416) Version 5.6.9 14 May 2015Core: Fixed bug #69467 (Wrong checked for the interface by Fixed bug #69324 (Buffer Over-read in unserialize when parsing Phar). (CVE-2015-2783, CVE-2015-3307) Fixed bug #69441 (Buffer Overflow when parsing tar/zip/phar in phar_set_inode). (CVE-2015-3329) Postgres: Fixed bug #68741 (Null pointer dereference). (CVE-2015-1352) Fixed bug #72693 (mb_ereg_search increments search position when a match zero-width). Fixed bug #72613 (Inadequate error handling in bzread()). (CVE-2016-5399) Date: Fixed bug #66836 (DateTime::createFromFormat 'U' with pre 1970 dates fails parsing).

JSON : Fixed bug #64695 (JSON_NUMERIC_CHECK has issues with strings that are numbers plus the letter e). mbstring: Fixed bug #72691 (mb_ereg_search raises a warning if a match zero-width). DOM: Fixed bug #73150 (missing NULL check in dom_document_save_html). Fixed bug #69418 (CVE-2006-7243 fix regressions in 5.4+). (CVE-2015-4025) Fixed bug #69522 (heap buffer overflow in unpack()).

Mysqlnd: Fixed bug #70456 (mysqlnd doesn't activate TCP keep-alive when connecting to a server). Fixed bug #70019 (Files extracted from archive may be placed outside of destination directory). (CVE-2015-6833) SOAP: Fixed bug #70081 (SoapClient info leak / null pointer dereference via multiple type confusions). Opcache: Fixed bug #69549 (Memory leak with opcache.optimization_level=0xFFFFFFFF).

Add CURLPROXY_SOCKS4A and CURLPROXY_SOCKS5_HOSTNAME constants if supported by libcurl. Fixed bug #69472 (php_sys_readlink ignores misc errors from GetFinalPathNameByHandleA).