5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
0.077 Low
EPSS
Percentile
94.2%
Memory leak in the timezone functionality in PHP before 5.3.9 allows remote
attackers to cause a denial of service (memory consumption) by triggering
many strtotime function calls, which are not properly handled by the
php_date_parse_tzfile cache.
Author | Note |
---|---|
sbeattie | patch is invasive and changes some interfaces, likely to introduce regressions |
mdeslaur | too intrusive to fix, marking as “ignored” |