CVE-2013-6712

PHP through 5.5.6 - Denial of Service via DateInterval Parsing

Title source: llm
STIX 2.1

Description

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.

References (10)

Core 10
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2816
Third Party Advisory vendor-advisory x_refsource_hp
https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322
Third Party Advisory x_refsource_confirm
https://support.apple.com/HT204659
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-12/msg00126.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-12/msg00125.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1765.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2055-1
Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://bugs.php.net/bug.php?id=66060

Scores

EPSS 0.1730
EPSS Percentile 95.1%

Details

CWE
CWE-119
Status published
Products (13)
apple/mac_os_x < 10.10.2
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 12.10
canonical/ubuntu_linux 13.04
canonical/ubuntu_linux 13.10
debian/debian_linux 6.0
debian/debian_linux 7.0
opensuse/opensuse 11.4
opensuse/opensuse 12.2
... and 3 more
Published Nov 28, 2013
Tracked Since Feb 18, 2026