Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:19306
HistoryMay 16, 2019 - 2:59 a.m.

Denial Of Service (DoS)

2019-05-1602:59:59
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.01 Low

EPSS

Percentile

83.7%

PHP is vulnerable to denial of service(DoS) attacks. This is because the ext/intl/msgformat/msgformat_parse.c does not restrict the locale length which allows remote attacker to cause stack-based buffer overflow and application crash or possibly have unspecified other impact within International Components for Unicode (ICU) for C/C++ via a long first argument to the msgfmt_parse_message function.