-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 23 Jan 2026 17:17:09 +0100 Source: php7.4 Architecture: source Version: 7.4.33-1+deb11u10 Distribution: bullseye-security Urgency: high Maintainer: Debian PHP Maintainers <team+pkg-php@tracker.debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 1123574 Changes: php7.4 (7.4.33-1+deb11u10) bullseye-security; urgency=high . * Non-maintainer upload by the LTS Team. * Fix CVE-2025-14177: Information Leak of Memory in getimagesize(). (Closes: #1123574) * Fix CVE-2025-14178: Heap buffer overflow in array_merge(). (Closes: #1123574) * Fix GHSA-www2-q4fc-65wf: Null byte termination in dns_get_record(). Checksums-Sha1: fe468acb8ce18f81058b3404ac2ab252d820d75f 5702 php7.4_7.4.33-1+deb11u10.dsc 4d3152b2339332b4eef2c12931931d4a1245fdab 10420144 php7.4_7.4.33.orig.tar.xz 1701962351f13c1af1f29bde45eb9515747bc4ee 833 php7.4_7.4.33.orig.tar.xz.asc efefde478a75ee280c24d4621b8408b3596fa736 126792 php7.4_7.4.33-1+deb11u10.debian.tar.xz b29f654ce7dad78d765dcde938eeb12644c84652 8001 php7.4_7.4.33-1+deb11u10_source.buildinfo Checksums-Sha256: d60219f9f042905beacc161c5cda9ae1016c91784b9a545bd9e04814f3981b7e 5702 php7.4_7.4.33-1+deb11u10.dsc 924846abf93bc613815c55dd3f5809377813ac62a9ec4eb3778675b82a27b927 10420144 php7.4_7.4.33.orig.tar.xz 569a01c7c605a4571fdf7dfadfff4215cc4a63ea5d474c7ec92bd7b4fecfffcb 833 php7.4_7.4.33.orig.tar.xz.asc 034ff25264d885d71fdfb2478a8494059c33db90b22d982a18fbf38c0bf8ff85 126792 php7.4_7.4.33-1+deb11u10.debian.tar.xz 8c14648bb54e8ea4a893ccf444f1e1911c2930674a382033009b0d49ed90e925 8001 php7.4_7.4.33-1+deb11u10_source.buildinfo Files: e3a03a81638d8bbce515d3ba545ce9cd 5702 php optional php7.4_7.4.33-1+deb11u10.dsc f098632163cd47f2c1ffe2bdc6ef1ff2 10420144 php optional php7.4_7.4.33.orig.tar.xz 306dca821388f20fa55324960d82f427 833 php optional php7.4_7.4.33.orig.tar.xz.asc 2787a9fca59843d8fba7ad9461717f69 126792 php optional php7.4_7.4.33-1+deb11u10.debian.tar.xz ff25ffb0fca131d07eda63079dad74e4 8001 php optional php7.4_7.4.33-1+deb11u10_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAml0eVUACgkQ05pJnDwh pVKjHw//dA05wD4Dzr03tDT5qKZpRSwkvu9HRDEtGvqVXNiMJMKf9mPl0greel26 OBMOe5e1Qq0pzMSVSj0v4+7KUhxy1G1YqUrqsY9mRXtc6Q/sgnPygah28nHBTE81 w6iFCQ5NmJrIzxEmpGkl8VMQtT+3LVgGI2imd3th+h/FQnuh6zk8ZJ9AJOMGCNDo fcAZylhJZ8i+gfKET9oo2oY7HLmBPZUr5+ASn5kZNmy3a8Y/vv6A1rznr+Zct4wR harSfnEEWvAnhKuASldpWu+O5Jdc7sJCmGMNxUSqNR8pLQwh+O1ZhJng0ysA24Lm xCQxAC3wbiguk1Lbu7k8iog8ng1//d7rtLQkdrJ+G8Pokls09Nvm+WmZiaKLMqeH 425Nc58eL7/9LP4VQdho8kVAwrtn/ZSTKv7q31sFv8WazXzXiZB6CntE2E6c0qWQ jLVRNtKnmgrDt10TphhmMEOXtaZB8nLfSza/6qZZFfl4/HnOST1R6lfrunCJdnNI /V7k6L+jUVHGYaE2z3SpuaR+Qu6OsB1T3wy+DWTIPF+KF6jXiNQap7O0AoZNKVDg KPdaydlYBwt2Hej36uoBGZ0JJ7z9opMeOMRwmD+J1uq9BcZrvMlfZ/cnlA/A+TF1 BGi5Or2M6GMX5WdbIcCNIXL5Q6cjw/m/OjEKCtQqTpuKXGROqFI= =E01O -----END PGP SIGNATURE-----