CVE-2017-16642
07.11.2017, 21:29
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.Enginsight
Vendor | Product | Version |
---|---|---|
php | php | 𝑥 < 5.6.32 |
php | php | 7.0.0 ≤ 𝑥 < 7.0.25 |
php | php | 7.1.0 ≤ 𝑥 < 7.1.11 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
canonical | ubuntu_linux | 14.04 |
netapp | storage_automation_store | - |
netapp | clustered_data_ontap | - |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References