Re: [PHP-DEV] CVE-2014-8142 is not mentioned in 5.6.4 changelog

2014-12-25 Thread Lior Kaplan
Fixed. http://git.php.net/?p=web/php.git;a=commitdiff;h=52cb11fca4c343f0529ceecfdc5372b49b966435 (should be refreshed on the website soon enough) On Wed, Dec 24, 2014 at 6:58 AM, Yasuo Ohgaki wrote: > Hi, > > http://php.net/ChangeLog-5.php#5.4.36 > does not mention CVE-2014-8142. > > Fixed bug

[PHP-DEV] CVE-2014-8142 is not mentioned in 5.6.4 changelog

2014-12-23 Thread Yasuo Ohgaki
Hi, http://php.net/ChangeLog-5.php#5.4.36 does not mention CVE-2014-8142. Fixed bug #68594 (Use after free vulnerability in unserialize()). should be Fixed bug #68594 (Use after free vulnerability in unserialize())(CVE-2014-8142). like 5.5/5.4's changelog. Regards, -- Yasuo Ohgaki yohg...@ohgak