PHP 5.6.40-14 with two backported security patches from PHP 7.2.33 has been released.
PHP 5.6.40-14
Backported from 7.2.33
- Core:
. Fixed bug #79877 (getimagesize function silently truncates after a null byte) (cmb)
- Phar:
. Fixed bug #79797 (Use of freed hash key in the phar_parse_zipfile function). (CVE-2020-7068) (cmb)
Download PHP 5.6.40-14 from GitHub