summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorFerenc Kovacs <tyrael@php.net>2014-12-17 01:59:38 +0100
committerFerenc Kovacs <tyrael@php.net>2014-12-17 01:59:38 +0100
commitc6a7d1eaed6c0d6bc83c8147018e28e2f28ba4a5 (patch)
treef24d87c4eb621b673335dc57c909a85cb77a840f
parent681a1afd3f76e97b243184e83ab826633e851cc3 (diff)
downloadphp-git-c6a7d1eaed6c0d6bc83c8147018e28e2f28ba4a5.tar.gz
add NEWS entry for #68594
-rw-r--r--NEWS2
1 files changed, 2 insertions, 0 deletions
diff --git a/NEWS b/NEWS
index 64ab8e2af4..ce88105444 100644
--- a/NEWS
+++ b/NEWS
@@ -80,6 +80,8 @@ PHP NEWS
. Fixed bug #68545 (NULL pointer dereference in unserialize.c). (Anatol)
. Fixed bug #68446 (Array constant not accepted for array parameter default).
(Bob, Dmitry)
+ . Fixed bug #68594 (Use after free vulnerability in unserialize()).
+ (CVE-2014-8142) (Stefan Esser)
- Date:
. Fixed day_of_week function as it could sometimes return negative values