Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:19311
HistoryMay 16, 2019 - 2:59 a.m.

Information Disclosure

2019-05-1602:59:59
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.006 Low

EPSS

Percentile

79.4%

PHP is vulnerable to information disclosure vulnerability. This is because an error in the date extension’s timelib_meridian handling of ‘front of’ and ‘back of’ directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function.