DateInterval of the file ext/date/lib/parse_iso_intervals.c of the component OBJECT Handler. Applying the patch Fixed bug #66060 (Heap buffer over-read in DateInterval) is able to eliminate this problem. The bugfix is ready for download at git.php.net. A possible mitigation has been published immediately after the disclosure of the vulnerability. Furthermore it is possible to detect and prevent this kind of attack with TippingPoint and the filter 13821.
Intelligence View
SOCIAL SHARE CARD GENERATOR