Back

MEDIUM

php: heap-based buffer over-read in DateInterval

Published Nov 28, 2013

Description

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.

Affected products

Remediation

Red Hat statement

This issue did not affect the php packages as shipped with Red Hat Enterprise Linux 5. This issue did not affect the php packages as shipped with Red Hat Enterprise Linux 7.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 28, 2013
Updated Aug 6, 2024
Reserved Nov 8, 2013
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 27, 2013