經過4個RC版,PHP 5.3.9正式版總算發布了。2012-01-11 上一個版本還是2011-08-23的5.3.8 這個版本當然修正了那個hash 碰撞攻擊bug.此外還有大量的bug修正,請使用PHP 5.3的同學盡快升級
Security Enhancements and Fixes in PHP 5.3.9:
Added max_input_vars directive to prevent attacks based on hash collisions. (CVE-2011-4885)
Fixed bug #60150 (Integer overflow during the parsing of invalid exif header). (CVE-2011-4566)
Key enhancements in PHP 5.3.9 include:
Fixed bug #55475 (is_a() triggers autoloader, new optional 3rd argument to is_a and is_subclass_of).
Fixed bug #55609 (mysqlnd cannot be built shared)
Many changes to the FPM SAPI module
完全改進:http://www.php.net/ChangeLog-5.php#5.3.9
下載:http://cn.php.net/distributions/php-5.3.9.tar.bz2
原文:http://www.oschina.net/news/24706/php-5-3-9