CVE-2013-6712

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
phpphp
𝑥
< 5.3.29
phpphp
5.4.0 ≤
𝑥
< 5.4.24
phpphp
5.5.0 ≤
𝑥
< 5.5.8
applemac_os_x
𝑥
≤ 10.10.2
opensuseopensuse
11.4
opensuseopensuse
12.2
opensuseopensuse
12.3
opensuseopensuse
13.1
canonicalubuntu_linux
10.04
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
canonicalubuntu_linux
13.04
canonicalubuntu_linux
13.10
debiandebian_linux
6.0
debiandebian_linux
7.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php5
saucy
Fixed 5.5.3+dfsg-1ubuntu2.1
released
raring
Fixed 5.4.9-4ubuntu2.4
released
quantal
Fixed 5.4.6-1ubuntu1.5
released
precise
Fixed 5.3.10-1ubuntu3.9
released
lucid
Fixed 5.3.2-1ubuntu4.22
released