Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-6712

Опубликовано: 27 нояб. 2013
Источник: redhat
CVSS2: 2.6

Описание

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.

A buffer over-read flaw was found in the way the DateInterval class parsed interval specifications. An attacker able to make a PHP application parse a specially crafted specification using DateInterval could possibly cause the PHP interpreter to crash.

Отчет

This issue did not affect the php packages as shipped with Red Hat Enterprise Linux 5. This issue did not affect the php packages as shipped with Red Hat Enterprise Linux 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5phpNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Software Collectionsphp55-phpAffected
Red Hat Enterprise Linux 5php53FixedRHSA-2014:101206.08.2014
Red Hat Enterprise Linux 6phpFixedRHSA-2014:101206.08.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6php54-phpFixedRHSA-2014:176530.10.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSphp54-phpFixedRHSA-2014:176530.10.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUSphp54-phpFixedRHSA-2014:176530.10.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUSphp54-phpFixedRHSA-2014:176530.10.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7php54-phpFixedRHSA-2014:176530.10.2014

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1035670php: heap-based buffer over-read in DateInterval

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.

nvd
больше 11 лет назад

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.

debian
больше 11 лет назад

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through ...

github
около 3 лет назад

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.

fstec
больше 11 лет назад

Уязвимость программного обеспечения PHP, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

2.6 Low

CVSS2