CVE Database
/

CVE-2017-16642

Back to search

CVE-2017-16642

Published: Nov 7, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.

VendorProductVersions

n/a

n/a

affected
n/a

References

43133
exploit
x_refsource_EXPLOIT-DB
RHSA-2018:1296
vendor-advisory
x_refsource_REDHAT
101745
vdb-entry
x_refsource_BID
DSA-4081
vendor-advisory
x_refsource_DEBIAN
DSA-4080
vendor-advisory
x_refsource_DEBIAN
USN-3566-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:2519
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now