← Back

CVE-2013-6712

nvd nist
Published: Nov 28, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.

Affected (15)

Products: Php: Php · Apple: Mac Os X · Opensuse: Opensuse · +2 more
Show all products
1 product
Php
1 product
Mac Os X
1 product
Opensuse
1 product
Ubuntu Linux
1 product
Debian Linux
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Php
Before 5.3.29
From 5.4.0 to 5.4.24
From 5.5.0 to 5.5.8
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Up to 10.10.2
Opensuse
Version 11.4
Version 12.2
Version 12.3
Version 13.1
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 10.04
Version 12.04
Version 12.10
Version 13.04
Version 13.10
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 6.0
Version 7.0

References (20)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Issue TrackingPatchVendor Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.