CVE-2017-16642
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 26.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 26.37% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- php/php · debian/debian linux · canonical/ubuntu linux · netapp/storage automation store · netapp/clustered data ontap
- Source
- cve@mitre.org
References
- http://php.net/ChangeLog-5.phpIssue Tracking, Release Notes, Vendor Advisory
- http://php.net/ChangeLog-7.phpIssue Tracking, Release Notes, Vendor Advisory
- http://www.securityfocus.com/bid/101745Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1296Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2519
- https://bugs.php.net/bug.php?id=75055Issue Tracking, Vendor Advisory
- https://github.com/derickr/timelib/commit/aa9156006e88565e1f1a5f7cc088b18322d57536Issue Tracking, Patch, Third Party Advisory
- https://github.com/php/php-src/commit/5c0455bf2c8cd3c25401407f158e820aa3b239e1Issue Tracking, Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20181123-0001/Third Party Advisory
- https://usn.ubuntu.com/3566-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4080Third Party Advisory
- https://www.debian.org/security/2018/dsa-4081Third Party Advisory
- https://www.exploit-db.com/exploits/43133/Exploit, Issue Tracking, Third Party Advisory, VDB Entry
- http://php.net/ChangeLog-5.phpIssue Tracking, Release Notes, Vendor Advisory
- http://php.net/ChangeLog-7.phpIssue Tracking, Release Notes, Vendor Advisory
- http://www.securityfocus.com/bid/101745Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1296Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2519
- https://bugs.php.net/bug.php?id=75055Issue Tracking, Vendor Advisory
- https://github.com/derickr/timelib/commit/aa9156006e88565e1f1a5f7cc088b18322d57536Issue Tracking, Patch, Third Party Advisory
- https://github.com/php/php-src/commit/5c0455bf2c8cd3c25401407f158e820aa3b239e1Issue Tracking, Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20181123-0001/Third Party Advisory
- https://usn.ubuntu.com/3566-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4080Third Party Advisory
- https://www.debian.org/security/2018/dsa-4081Third Party Advisory
- https://www.exploit-db.com/exploits/43133/Exploit, Issue Tracking, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.