PHP Release 7.3.23


PHP 7.3.23 Release Announcement

The PHP development team announces the immediate availability of PHP 7.3.23. This is a security release.

All PHP 7.3 users are encouraged to upgrade to this version.

For source downloads of PHP 7.3.23 please visit our downloads page, Windows source and binaries can be found on windows.php.net/download/. The list of changes is recorded in the ChangeLog.

Source Code
PHP 7.3.23 (tar.bz2)
SHA256: fd6666ad4605508042c6964151379475daea36c43e03b11b1e79d4ae6b04c04c
PHP 7.3.23 (tar.gz)
SHA256: a21094b9ba2d8fe7fa5838e6566e30cf4bfaf2c8a6dce90ff707c45d0d8d494d
PHP 7.3.23 (tar.xz)
SHA256: 2bdd36176f318f451fb3942bf1e935aabb3c2786cac41a9080f084ad6390e034
Change Logs
core
  • Fixed bug #80048 (Bug #69100 has not been fixed for Windows).
  • Fixed bug #80049 (Memleak when coercing integers to string via variadic argument).
  • Fixed bug #79699 (PHP parses encoded cookie names so malicious `__Host-` cookies can be sent). (CVE-2020-7070)
calendar
  • Fixed bug #80007 (Potential type confusion in unixtojd() parameter parsing).
com
  • Fixed bug #64130 (COM obj parameters passed by reference are not updated).
opcache
  • Fixed bug #80002 (calc free space for new interned string is wrong).
  • Fixed bug #79825 (opcache.file_cache causes SIGSEGV when custom opcode handlers changed).
openssl
  • Fixed bug #79601 (Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV). (CVE-2020-7069)
pdo
  • Fixed bug #80027 (Terrible performance using $query->fetch on queries with many bind parameters).
soap
  • Fixed bug #47021 (SoapClient stumbles over WSDL delivered with "Transfer-Encoding: chunked").
standard
  • Fixed bug #79986 (str_ireplace bug with diacritics characters).
  • Fixed bug #80077 (getmxrr test bug).
  • Fixed bug #72941 (Modifying bucket->data by-ref has no effect any longer).
  • Fixed bug #80067 (Omitting the port in bindto setting errors).
To Top