Statement on glibc/iconv Vulnerability

PHP 7.4.33 Release Announcement

The PHP development team announces the immediate availability of PHP 7.4.33.

This is security release that fixes an OOB read due to insufficient input validation in imageloadfont(), and a buffer overflow in hash_update() on long parameter.

All PHP 7.4 users are encouraged to upgrade to this version.

For source downloads of PHP 7.4.33 please visit our downloads page, Windows source and binaries can be found on windows.php.net/download/. The list of changes is recorded in the ChangeLog.

To Top