TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

PHP 5.3.7 Released

39 点作者 Popcorned23将近 14 年前

4 条评论

randallsquared将近 14 年前
<i>mysqlnd<p>Fixed crash when using more than 28,000 bound parameters. Workaround is to set mysqlnd.net_cmd_buffer_size to at least 9000. (Andrey)</i><p>Whew. Thank goodness that's fixed?
评论 #2900529 未加载
评论 #2900475 未加载
jbyers将近 14 年前
Just bug fixes? If you allow file uploads, you would be wise to upgrade.<p>Fixed bug #54939 (File path injection vulnerability in RFC1867 File upload filename). Reported by Krzysztof Kotowicz. (CVE-2011-2202)<p>"The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwrite arbitrary files, via a crafted upload request, related to a "file path injection vulnerability."
andre将近 14 年前
Looks like mostly bug fixes.
debaserab2将近 14 年前
High level overview anyone?
评论 #2900446 未加载
评论 #2900445 未加载