The PHP development team announces the immediate availability of PHP 7.4.33. This is security release that fixes an OOB read due to insufficient input validation in imageloadfont(), and a buffer overflow in hash_update() on long parameter. All PHP 7.4 users are encouraged to upgrade to this version. This is the last PHP 7.4 release, and no further security releases will be created. For source downloads of PHP 7.4.33 please visit our downloads page. Windows binaries can be found on the PHP for Windows site. The list of changes is recorded in the ChangeLog. A migration guide is available in the PHP Manual. Please consult it for the detailed list of new features and backward incompatible changes. Release Announcement: <https://www.php.net/releases/7_4_33.php> Downloads: <https://www.php.net/downloads> Windows downloads: <https://windows.php.net/download> Changelog: <https://www.php.net/ChangeLog-7.php#7.4.33> Migration guide: <https://www.php.net/manual/migration74.php> Many thanks to all the contributors and supporters! Derick Rethans P.S. Below is the verification information for the downloads, which is also available on <https://gist.github.com/derickr/19b147b6d2f014858a166484c599f944>. php-7.4.33.tar.gz SHA256 hash: 5a2337996f07c8a097e03d46263b5c98d2c8e355227756351421003bea8f463e PGP signature: -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEWlKIB4H3VWCL+BX8kQ3rRvU+oxIFAmNftBIACgkQkQ3rRvU+ oxLSuRAAxLCfYYOQ25Q/svXyBjqylG/2zpd95PBTp0zxlVisqR6+QsYnHo5jMkqm JIjI+aqA9XCrz7ftUIOB98JvvaDKSMkLOxYPN18yjdzf1XRDZdYzU67FwmO5XmVD kW7u0oXE2cXl1KaNVNNWEdvD9n0TuHJIkMYZ8XiFsNVQ0YiIy2kNX8OeKkvxpHq7 VgA5wi5Y7HiS/L2JwYPgbrMn9XgzDPvg8zh9QM7fYXCGWEGSsLyIe7Ff60P+hhHY 7qUKcHe2T3GVnrZDmoA/gejbNfcYOpD4x7iEOO+nMEr+mmrF4ELDRHLq0HRoTx4A zWfVw11PP5STBxnmOjZgBV0scckEcImtEYZAaDnBCkpAEXJmulSmx17hLA8blqBv 8+n910N4VXEFqgJCDQA4mXb4tjZODX1FORYJjsHZ9LIKyvg/x6m4mvuTUUbTTjj1 Y7WZqUDbeNJEso/hePz91uduGx+cOoOBmssm2ohRllQlLAlr35k4Yr3RhYWAp410 JTCWWqMBcWa4VcqKV+N+y74y79rAe/5Mfd/S+O8NejuPdGxbstcU3tgw7GRrDZox xiGMVwcNLzCsgYTxJOQJ/y1FHhJcVXiqb4Fhn9rOxFEIamuOogUGtO6sZddquZpD VzhqdKDBDLjdZHtGMOAaU2/GpLxXSuu6hsWnNv7z8Fo8Gz48ki8= =uEyB -----END PGP SIGNATURE----- php-7.4.33.tar.bz2 SHA256 hash: 4e8117458fe5a475bf203128726b71bcbba61c42ad463dffadee5667a198a98a PGP signature: -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEWlKIB4H3VWCL+BX8kQ3rRvU+oxIFAmNftBYACgkQkQ3rRvU+ oxJpwBAAiolQDbhXw7jNNBDPqtwAjedOZy+M0MKq3PbOy4POXlYAQ7Us1V/aOOyf PBGUigZ3/2l3mAnCmmXFmTSAc6khQzW2uu1BGMJOLV8HL8BV8j0yMCjuotdUhso1 QIPY5SMN/vIOd2wB0fX6SPjY5U1gCJIwu4wKn3aM3lteYub6h6H8GTkM1NRwSjhU nLrZg0dbmBanLWlwt8fWcPzN76um4U4v9JPZbx9l7kcBARBitsMV64N5dgJUjktm p3TrU96pj5Cbj3ondTgBVk0613lxPHF5nETBdumso1tyM6Oje0Uy5ZoCX9yOFI3w uzfQ+oJmglT2Q53G0zsW5cp4uWXACVsFQqG/v2pWZ0sEsPTt0n3Jha3tZ4YAnuF2 hglbCxBxDw6zQGaHraGgXFYfqwmx2g1/f1Rn/Djgla3O+1DuPKT9Dlgm12YNcIAk jiP/Z/KDHHglYkvLlF/W8uCalu0TNbX6TZTNhiKaWJXtJoM2XXVf1Elt+yIoRlp7 qI6xHsG2ySWZmd4fIAdRhNYnIxRM+ASvFCvEl8QPczWGSR2l4C+iXJCvzAp9f4Q8 GEQOcRm+FKS8AkvyxRZ16etJ7MPZb4YN8aErwK57FmZlOIUxXCksF3RgM7EGtxBx nGz9tkZkqxdGpO9e0bFsVum3dJpWYnE37dsYBgwcdaKGPw4UXKI= =7PeD -----END PGP SIGNATURE----- php-7.4.33.tar.xz SHA256 hash: 924846abf93bc613815c55dd3f5809377813ac62a9ec4eb3778675b82a27b927 PGP signature: -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEWlKIB4H3VWCL+BX8kQ3rRvU+oxIFAmNftBYACgkQkQ3rRvU+ oxKEJw/7B1ynCpmaLJD9H8YB6YkRdaQ7s4jX10wHrCL2mYFcrViPokJUPHymQ4cG LYYLDxqhziH5a61ZE0QwBqDSthMuW6KHx4bod7DPXT2vb+wI4KGWWLLjRyb36QEU JWEYll0ITIy5SKLjQvQWz9Ti6NKs8fPDrty43rQYTXgHi4dnpC4iS1oS5bPQlozK d9yWoclOlsD1gQvJLfGmZkBhXMVc1ndDQAwQZexU0OGvy8qiSs3BNOwTrmwHlArr UQwBeuvQvoy7NvpMhBazkpt4VwxGx9iJkOKOBupHkqgnQRic9oFH4q1BsAoz/H27 jy9A6Qkru7x/z9tzFxGvYRa9JYu3ci+C1kNFG3IjkHpzHM9HAS1/2sXrV2RLY8DO PagxuSt5/6fYhPTmb4msl/UWGHZlewuFP2HucnIqnCw4/PW/33bqiZpoh/vXT9CH 1adgRptXeF5MHJH95m0OtRk1Mmw9vIRd0pU8GleJbW/ny5Ki4q+WxF3rb+QFRC4Z Mhi2trcicCNhGy2iD3bPhfCObPd9NW7csQorJUf/I7QBFZXFpVExK88axuwOwM5u pQA72mvFqRwhSSgMEL5U9RfLG1Is8zcnARs9BqoWtgP78sTPvqKzr2nJ3fzSfglS EQ40VNrGF4wsruOZf/Stx1v2ysrDHnZ+45Og0BxaRyfVBp+Q/70= =lvvn -----END PGP SIGNATURE----- -- PHP 7.4 Release Manager Host of PHP Internals News: https://phpinternals.news Like Xdebug? Consider supporting me: https://xdebug.org/support https://derickrethans.nl | https://xdebug.org | https://dram.io twitter: @derickr and @xdebug