In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, an error in the date extension's timelib_meridian parsing code could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: the correct fix is in the e8b7698f5ee757ce2c8bd10a192a491a498f891c commit, not the bd77ac90d3bdf31ce2a5251ad92e9e75 gist.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1034-1 | php5 security update |
Debian DSA |
DSA-4080-1 | php7.0 security update |
Debian DSA |
DSA-4081-1 | php5 security update |
EUVD |
EUVD-2017-2780 | In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, an error in the date extension's timelib_meridian parsing code could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: the correct fix is in the e8b7698f5ee757ce2c8bd10a192a491a498f891c commit, not the bd77ac90d3bdf31ce2a5251ad92e9e75 gist. |
Ubuntu USN |
USN-3382-1 | PHP vulnerabilities |
Ubuntu USN |
USN-3382-2 | PHP vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T17:57:57.684Z
Reserved: 2017-07-10T00:00:00
Link: CVE-2017-11145
No data.
Status : Deferred
Published: 2017-07-10T14:29:00.637
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-11145
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN