PT-2017-4179 · Php+3 · Php+3

Published

2017-07-08

·

Updated

2018-05-04

·

CVE-2017-11145

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.6.31 PHP versions 7.x prior to 7.0.21 PHP versions 7.1.x prior to 7.1.7
Description The issue is related to an error in the date extension's timelib meridian parsing code, which could be exploited by attackers to leak information from the interpreter. This is due to out-of-bounds reads affecting the php parse date function. The vulnerability allows remote attackers to impact the confidentiality of information by supplying date strings.
Recommendations For PHP versions prior to 5.6.31, update to version 5.6.31 or later. For PHP versions 7.x prior to 7.0.21, update to version 7.0.21 or later. For PHP versions 7.1.x prior to 7.1.7, update to version 7.1.7 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1822
BDU:2022-02422
CVE-2017-11145
DLA-1034-1
DSA-4080-1
DSA-4081-1
OPENSUSE-SU-2017_2337-1
RHSA-2018:1296
SUSE-SU-2017:2303-1
SUSE-SU-2017:2317-1
SUSE-SU-2017:2522-1
USN-3382-1
USN-3382-2

Affected Products

Alt Linux
Php
Suse
Ubuntu