Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11497
HistoryJan 15, 2019 - 9:02 a.m.

Denial Of Service (DoS)

2019-01-1509:02:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.59 Medium

EPSS

Percentile

97.8%

php is vulnerable to denial of service (DoS) attacks. The vulnerability exists as the scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.