Opened 8 years ago

Closed 8 years ago

#6711 closed enhancement (fixed)


Reported by: Fernando de Oliveira Owned by: bdubbs@…
Priority: high Milestone: 7.8
Component: BOOK Version: SVN
Severity: normal Keywords:




Also it was once recommended, but I don't know if it is still true:



mysqlnd allows downgrade to non-SSL connection even if SSL was requested

Also see:

MySQL, Oracle’s relational database management system, is plagued by a vulnerability that can be exploited to downgrade SSL/TLS connections, according to researchers at Duo Security.

md5: a0c842c1d30fedbe972e1556ae9cee27

Version 5.6.11
10 Jul 2015

   • Core:
        • Fixed bug #69768 (escapeshell*() doesn't cater to !).
        • Fixed bug #69703 (Use __builtin_clzl on PowerPC).
        • Fixed bug #69732 (can induce segmentation fault with basic php
        • Fixed bug #69642 (Windows 10 reported as Windows 8).
        • Fixed bug #69551 (parse_ini_file() and parse_ini_string()
          segmentation fault).
        • Fixed bug #69781 (phpinfo() reports Professional Editions of
          Windows 7/8/8.1/10 as "Business").
        • Fixed bug #69740 (finally in generator (yield) swallows
          exception in iteration).
        • Fixed bug #69835 (phpinfo() does not report many Windows
        • Fixed bug #69892 (Different arrays compare indentical due to
          integer key truncation).
        • Fixed bug #69874 (Can't set empty additional_headers for
          mail()), regression from fix to bug #68776.
   • GD:
        • Fixed bug #61221 (imagegammacorrect function loses alpha
   • GMP:
        • Fixed bug #69803 (gmp_random_range() modifies second parameter
          if GMP number).
   • Mysqlnd:
        • Fixed bug #69669 (mysqlnd is vulnerable to BACKRONYM)
   • PCRE:
        • Fixed bug #53823 (preg_replace: * qualifier on unicode replace
          garbles the string).
        • Fixed bug #69864 (Segfault in preg_replace_callback) (cmb, ab)
   • PDO_pgsql:
        • Fixed bug #69752 (PDOStatement::execute() leaks memory with
          DML Statements when closeCuror() is u).
        • Fixed bug #69362 (PDO-pgsql fails to connect if password
          contains a leading single quote).
        • Fixed bug #69344 (PDO PgSQL Incorrect binding numeric array
          with gaps).
   • SimpleXML:
        • Refactored the fix for bug #66084 (simplexml_load_string()
          mangles empty node name).
   • SPL:
        • Fixed bug #69737 (Segfault when SplMinHeap::compare produces
          fatal error).
        • Fixed bug #67805 (SplFileObject setMaxLineLength). (Willian
          Gustavo Veiga).
        • Fixed bug #69970 (Use-after-free vulnerability in
   • Sqlite3:
        • Fixed bug #69972 (Use-after-free vulnerability in

Change History (4)

comment:1 by Fernando de Oliveira, 8 years ago

Owner: changed from blfs-book@… to Fernando de Oliveira
Status: newassigned

comment:2 by Fernando de Oliveira, 8 years ago

Owner: changed from Fernando de Oliveira to blfs-book@…
Status: assignednew

comment:3 by bdubbs@…, 8 years ago

Owner: changed from blfs-book@… to bdubbs@…
Status: newassigned

comment:4 by bdubbs@…, 8 years ago

Resolution: fixed
Status: assignedclosed

Fixed at revision 16239.

Note: See TracTickets for help on using tickets.