Home » Releases » 7.0 » 7.0.33 »

PHP 7.0.3

PHP 7.0 is no longer officially supported by the PHP project.

Official support refers to that provided direct by the PHP Project.

If you install PHP via third-party packages, support timelines may be different. Please read the Release Support Policy for more information.

The latest release of PHP 7.0 is 7.0.33 which includes important security patches.

Source Code

  • PHP 7.0.3 (tar.bz2)

    • sha256: 826823d754f09c779222a99becf9c53a4dc719dba2d777aca7807c6ca68e6fc6
  • PHP 7.0.3 (tar.gz)

    • sha256: 5521df8db153aba35c90cf1a1829106b6bbdac32425216d440f9cc29f00a7c08
  • PHP 7.0.3 (tar.xz)

    • sha256: 3af2b62617a0e46214500fc3e7f4a421067224913070844d3665d6cc925a1cca

Change Log

  • core

    • Added support for new HTTP 451 code.
      Julien
    • Fixed bug #71039 (exec functions ignore length but look for NULL termination).
      Anatol
    • Fixed bug #71089 (No check to duplicate zend_extension).
      Remi
    • Fixed bug #71201 (round() segfault on 64-bit builds).
      Anatol
    • Fixed bug #71221 (Null pointer deref (segfault) in get_defined_vars via ob_start).
      hugh at allthethings dot co dot nz
    • Fixed bug #71248 (Wrong interface is enforced).
      Dmitry
    • Fixed bug #71273 (A wrong ext directory setup in php.ini leads to crash).
      Anatol
    • Fixed Bug #71275 (Bad method called on cloning an object having a trait).
      Bob
    • Fixed bug #71297 (Memory leak with consecutive yield from).
      Bob
    • Fixed bug #71300 (Segfault in zend_fetch_string_offset).
      Laruence
    • Fixed bug #71314 (var_export(INF) prints INF.0).
      Andrea
    • Fixed bug #71323 (Output of stream_get_meta_data can be falsified by its input).
      Leo Gaspard
    • Fixed bug #71336 (Wrong is_ref on properties as exposed via get_object_vars()).
      Laruence
    • Fixed bug #71459 (Integer overflow in iptcembed()).
      Stas
  • apache2handler

    • Fix >2G Content-Length headers in apache2handler.
      Adam Harvey
  • curl

    • Fixed bug #71227 (Can't compile php_curl statically).
      Anatol
    • Fixed bug #71225 (curl_setopt() fails to set CURLOPT_POSTFIELDS with reference to CURLFile).
      Laruence
  • gd

    • Improved fix for bug #70976.
      Remi
  • interbase

    • Fixed Bug #71305 (Crash when optional resource is omitted).
      Laruence
      Anatol
  • ldap

    • Fixed bug #71249 (ldap_mod_replace/ldap_mod_add store value as string "Array").
      Laruence
  • mbstring

    • Fixed bug #71397 (mb_send_mail segmentation fault).
      Andrea
      Yasuo
  • openssl

    • Fixed bug #71475 (openssl_seal() uninitialized memory usage).
      Stas
  • pcre

    • Upgraded pcrelib to 8.38.
      CVE-2015-8383
      CVE-2015-8386
      CVE-2015-8387
      CVE-2015-8389
      CVE-2015-8390
      CVE-2015-8391
      CVE-2015-8393
      CVE-2015-8394
  • phar

    • Fixed bug #71354 (Heap corruption in tar/zip/phar parser). (CVE-2016-4342)
      Stas
    • Fixed bug #71331 (Uninitialized pointer in phar_make_dirstream()). (CVE-2016-4343)
      Stas
    • Fixed bug #71391 (NULL Pointer Dereference in phar_tar_setupmetadata()).
      Stas
    • Fixed bug #71488 (Stack overflow when decompressing tar archives). (CVE-2016-2554)
      Stas
  • soap

    • Fixed bug #70979 (crash with bad soap request).
      Anatol
  • spl

    • Fixed bug #71204 (segfault if clean spl_autoload_funcs while autoloading).
      Laruence
    • Fixed bug #71202 (Autoload function registered by another not activated immediately).
      Laruence
    • Fixed bug #71311 (Use-after-free vulnerability in SPL(ArrayObject, unserialize)).
      Sean Heelan
    • Fixed bug #71313 (Use-after-free vulnerability in SPL(SplObjectStorage, unserialize)).
      Sean Heelan
  • standard

    • Fixed bug #71287 (Error message contains hexadecimal instead of decimal number).
      Laruence
    • Fixed bug #71264 (file_put_contents() returns unexpected value when filesystem runs full).
      Laruence
    • Fixed bug #71245 (file_get_contents() ignores "header" context option if it's a reference).
      Laruence
    • Fixed bug #71220 (Null pointer deref (segfault) in compact via ob_start).
      hugh at allthethings dot co dot nz
    • Fixed bug #71190 (substr_replace converts integers in original $search array to strings).
      Laruence
    • Fixed bug #71188 (str_replace converts integers in original $search array to strings).
      Laruence
    • Fixed bug #71132, #71197 (range() segfaults).
      Thomas Punt
  • wddx

    • Fixed bug #71335 (Type Confusion in WDDX Packet Deserialization).
      Stas

PHP 7.0


  Represents a security release