CVE-2017-16642: High severity PHP PHP vulnerability
Fixed bug (Out-Of-Bounds Read in timelibmeridian()). (CVE-2017-16642)
Other sources
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an e ...
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 7.0.25 - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 7.1.11 - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 7.2.0 - Upgrade
Upgrade
PHPto a version that resolves this vulnerability.Fixed in 7.0.25 - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 5.6.32 - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 7.0.25 - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 7.1.11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 5c0455bf2c8cd3c25401407f158e820aa3b239e1 - Compensating control
Ensure that attackers cannot supply attacker-controlled date strings to the vulnerable date extension code path (ext/date, timelib_meridian / php_parse_date) in any context where information leakage would be impactful.
Event History
Frequently Asked Questions
What is the vulnerability ID of this bug?
The vulnerability ID is CVE-2017-16642.
What is the severity level of CVE-2017-16642?
The severity level of CVE-2017-16642 is high.
What is the affected software for CVE-2017-16642?
The affected software for CVE-2017-16642 is PHP versions before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11.
How can this vulnerability be exploited?
Attackers able to supply date strings can exploit this vulnerability to leak information from the interpreter.
Is there a fix available for CVE-2017-16642?
Yes, the fix for CVE-2017-16642 is available in PHP versions 5.6.32, 7.0.25, and 7.1.11.