Stefan Esser has a post to the PHP Security Blog about his "Month of PHP Bugs" (March 2007) that will be happening and some of the new effects that the recent release of PHP 5.2.1 has had on it.
Today PHP 5.2.1 was released which fixes some (but not all) of the bugs I will cover in the "Month of PHP bugs". Actually the release announcement already gives a list of bugs that were fixed.
He also comments on the reporting of the bugs in the Changelog and updates in the release announcements and how they're handled.