Back

HIGH

php: xmlrpc ISO8601 date format parsing buffer overflow

Published Nov 23, 2014

Description

Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding.

Affected products

Remediation

Red Hat statement

This issue did not affect php53 packages in Red Hat Enterprise Linux 5, php packages in Red Hat Enterprise Linux 6 and 7, and php54-php and php55-php packages in Red Hat Software Collections 1.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 23, 2014
Updated Aug 6, 2024
Reserved Nov 6, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Nov 5, 2014