VulnerabilityModified
CVE-2013-4635
Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish…
MEDIUM 5.0EPSS 4.23%
Does this matter?
Lower severity and a low EPSS score (4.23%). Track it; it rarely justifies an emergency change on its own.
Description
Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish function.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 4.23% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- php/php
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00034.html
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00007.html
- http://secunia.com/advisories/54104
- http://www.attrition.org/pipermail/vim/2013-June/002697.html
- http://www.php.net/ChangeLog-5.phpVendor Advisory
- http://www.securitytracker.com/id/1028699
- http://www.ubuntu.com/usn/USN-1905-1
- https://bugs.php.net/bug.php?id=64895
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00034.html
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00007.html
- http://secunia.com/advisories/54104
- http://www.attrition.org/pipermail/vim/2013-June/002697.html
- http://www.php.net/ChangeLog-5.phpVendor Advisory
- http://www.securitytracker.com/id/1028699
- http://www.ubuntu.com/usn/USN-1905-1
- https://bugs.php.net/bug.php?id=64895
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.