U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2017-11146

Change History

CVE Modified by MITRE 7/23/2017 9:29:00 PM

Action Type Old Value New Value
Removed CPE Configuration
OR
     *cpe:2.3:a:php:php:5.6.30:*:*:*:*:*:*:* (and previous)
     *cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.6:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.7:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.8:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.9:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.10:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.11:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.12:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.13:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.14:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.15:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.16:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.17:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.18:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.19:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.20:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.0.21:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.1.0:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.1.1:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.1.2:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.1.3:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.1.4:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.1.5:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.1.6:*:*:*:*:*:*:*
     *cpe:2.3:a:php:php:7.1.7:*:*:*:*:*:*:*

								
						
Removed CVSS V2
(AV:N/AC:L/Au:N/C:P/I:N/A:N)

								
						
Removed CVSS V3
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

								
						
Removed CWE
CWE-200

								
						
Changed Description
In PHP through 5.6.31, 7.x through 7.0.21, and 7.1.x through 7.1.7, lack of bounds checks in the date extension's timelib_meridian parsing code could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-11145.
** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not an independently fixable security issue relative to CVE-2017-11145.  Notes: none.
Changed Display Vulnerability
true
false
Removed Reference
http://openwall.com/lists/oss-security/2017/07/10/6 [Mailing List, Third Party Advisory]

								
						
Removed Reference
http://www.securityfocus.com/bid/99612 [No Types Assigned]

								
						
Removed Reference
https://bugs.php.net/bug.php?id=74819 [Third Party Advisory]

								
						
Removed Reference
https://gist.github.com/anonymous/bd77ac90d3bdf31ce2a5251ad92e9e75 [Patch, Third Party Advisory]