{"schema_version":"1.8.0","id":"CVE-2017-11145","published":"2017-07-10T14:29:00.637Z","modified":"2026-08-07T14:48:41.131768Z","related":["SUSE-SU-2017:2303-1","SUSE-SU-2017:2317-1","SUSE-SU-2017:2522-1"],"details":"In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, an error in the date extension's timelib_meridian parsing code could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: the correct fix is in the e8b7698f5ee757ce2c8bd10a192a491a498f891c commit, not the bd77ac90d3bdf31ce2a5251ad92e9e75 gist.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/php/php-src","events":[{"introduced":"0"},{"last_affected":"195427c55481d9913ac9dd3fbcedf2f7c637e6de"},{"introduced":"60fffd296abce5fc071f3c173c25a2696cf683c6"},{"last_affected":"5b34dc2d52841bfab425cbb24e9111172de20ef9"}],"database_specific":{"cpe":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.6:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.7:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.8:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.9:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.10:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.11:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.12:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.13:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.14:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.15:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.16:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.17:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.18:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.19:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.20:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.2:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.3:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.5:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.6:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"5.6.30"},{"introduced":"7.0.0"},{"last_affected":"7.0.0"},{"introduced":"7.0.1"},{"last_affected":"7.0.1"},{"introduced":"7.0.2"},{"last_affected":"7.0.2"},{"introduced":"7.0.3"},{"last_affected":"7.0.3"},{"introduced":"7.0.4"},{"last_affected":"7.0.4"},{"introduced":"7.0.5"},{"last_affected":"7.0.5"},{"introduced":"7.0.6"},{"last_affected":"7.0.6"},{"introduced":"7.0.7"},{"last_affected":"7.0.7"},{"introduced":"7.0.8"},{"last_affected":"7.0.8"},{"introduced":"7.0.9"},{"last_affected":"7.0.9"},{"introduced":"7.0.10"},{"last_affected":"7.0.10"},{"introduced":"7.0.11"},{"last_affected":"7.0.11"},{"introduced":"7.0.12"},{"last_affected":"7.0.12"},{"introduced":"7.0.13"},{"last_affected":"7.0.13"},{"introduced":"7.0.14"},{"last_affected":"7.0.14"},{"introduced":"7.0.15"},{"last_affected":"7.0.15"},{"introduced":"7.0.16"},{"last_affected":"7.0.16"},{"introduced":"7.0.17"},{"last_affected":"7.0.17"},{"introduced":"7.0.18"},{"last_affected":"7.0.18"},{"introduced":"7.0.19"},{"last_affected":"7.0.19"},{"introduced":"7.0.20"},{"last_affected":"7.0.20"},{"introduced":"7.1.0"},{"last_affected":"7.1.0"},{"introduced":"7.1.1"},{"last_affected":"7.1.1"},{"introduced":"7.1.2"},{"last_affected":"7.1.2"},{"introduced":"7.1.3"},{"last_affected":"7.1.3"},{"introduced":"7.1.4"},{"last_affected":"7.1.4"},{"introduced":"7.1.5"},{"last_affected":"7.1.5"},{"introduced":"7.1.6"},{"last_affected":"7.1.6"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["7.0.0","7.0.1","7.0.10","7.0.11","7.0.12","7.0.13","7.0.14","7.0.15","7.0.16","7.0.17","7.0.18","7.0.19","7.0.2","7.0.20","7.0.3","7.0.4","7.0.5","7.0.6","7.0.7","7.0.8","7.0.9","7.1.0","7.1.1","7.1.2","7.1.3","7.1.4","7.1.5","7.1.6","php-7.1.6","php-7.1.6RC1","php-5.6.30","php-5.6.30RC1","POST_PHP7_NSAPI_REMOVAL","PRE_PHP7_NSAPI_REMOVAL","PRE_PHP7_EREG_MYSQL_REMOVALS","PRE_PHP7_REMOVALS","POST_PHP7_REMOVALS","POST_AST_MERGE","PRE_AST_MERGE","POST_64BIT_BRANCH_MERGE","PRE_64BIT_BRANCH_MERGE","POST_PHPNG_MERGE"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-11145.json"}}],"references":[{"type":"WEB","url":"http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=e8b7698f5ee757ce2c8bd10a192a491a498f891c"},{"type":"WEB","url":"http://www.securityfocus.com/bid/99550"},{"type":"WEB","url":"https://www.tenable.com/security/tns-2017-12"},{"type":"ADVISORY","url":"http://openwall.com/lists/oss-security/2017/07/10/6"},{"type":"ADVISORY","url":"http://php.net/ChangeLog-5.php"},{"type":"ADVISORY","url":"http://php.net/ChangeLog-7.php"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1296"},{"type":"ADVISORY","url":"https://bugs.php.net/bug.php?id=74819"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20180112-0001/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4080"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4081"},{"type":"FIX","url":"https://gist.github.com/anonymous/bd77ac90d3bdf31ce2a5251ad92e9e75"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}