CVE-2017-16642

HIGH

PHP <5.6.32, 7.x <7.0.25, 7.1.x <7.1.11 - Info Disclosure

Title source: llm

Description

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Wei Lei and Liu Yang · phpdosmultiple
https://www.exploit-db.com/exploits/43133

Scores

CVSS v3 7.5
EPSS 0.0826
EPSS Percentile 92.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-125
Status published
Products (6)
canonical/ubuntu_linux 14.04
debian/debian_linux 8.0
debian/debian_linux 9.0
netapp/clustered_data_ontap
netapp/storage_automation_store
php/php < 5.6.32
Published Nov 07, 2017
Tracked Since Feb 18, 2026