CVE-2016-10712
published 2018-02-09CVE-2016-10712: In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
2.30%
81.3th percentile
In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = stream_get_meta_data(fopen($file, "r"))['uri']" call mishandles the case where $file is data:text/plain;uri=eviluri, -- in other words, metadata can be set by an attacker.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| php | php | <= 5.5.31 | — |
| php | php | 5.6.0 – 5.6.17 | — |
| php | php | 7.0.0 – 7.0.2 | — |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.24 | 5.5.9+dfsg-1ubuntu4.24 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.29+esm2 | 5.5.9+dfsg-1ubuntu4.29+esm2 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5jr3-87vw-j587: In PHP before 5
ghsa_unreviewed·2022-05-14
CVE-2016-10712 [HIGH] CWE-20 GHSA-5jr3-87vw-j587: In PHP before 5
In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = stream_get_meta_data(fopen($file, "r"))['uri']" call mishandles the case where $file is data:text/plain;uri=eviluri, -- in other words, metadata can be set by an attacker.
OSV
php5 vulnerabilities
osv·2019-05-22·CVSS 7.5
CVE-2018-20783 [HIGH] php5 vulnerabilities
php5 vulnerabilities
USN-3566-1 fixed several vulnerabilities in PHP. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
It was discovered that PHP incorrectly handled certain files. An attacker
could possibly use this issue to access sensitive information.
(CVE-2018-20783)
It was discovered that PHP incorrectly handled certain files. An attacker
could possibly use this issue to access sensitive information or possibly
cause a crash, resulting in a denial of service. (CVE-2019-11036)
Original advisory details:
It was discovered that PHP incorrectly handled memory when unserializing
certain data. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affect
OSV
php5, php7.0, php7.1 vulnerabilities
osv·2018-03-19·CVSS 7.5
CVE-2016-10712 [HIGH] php5, php7.0, php7.1 vulnerabilities
php5, php7.0, php7.1 vulnerabilities
It was discovered that PHP incorrectly handled certain stream metadata. A
remote attacker could possibly use this issue to set arbitrary metadata.
This issue only affected Ubuntu 14.04 LTS. (CVE-2016-10712)
It was discovered that PHP incorrectly handled the PHAR 404 error page. A
remote attacker could possibly use this issue to conduct cross-site
scripting (XSS) attacks. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 17.10. (CVE-2018-5712)
It was discovered that PHP incorrectly handled parsing certain HTTP
responses. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2018-7584)
OSV
CVE-2016-10712: In PHP before 5
osv·2018-02-09·CVSS 7.5
CVE-2016-10712 [HIGH] CVE-2016-10712: In PHP before 5
In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = stream_get_meta_data(fopen($file, "r"))['uri']" call mishandles the case where $file is data:text/plain;uri=eviluri, -- in other words, metadata can be set by an attacker.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2019-05-22·CVSS 7.5
CVE-2016-10712 [HIGH] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
USN-3566-1 fixed several vulnerabilities in PHP. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
It was discovered that PHP incorrectly handled certain files. An attacker
could possibly use this issue to access sensitive information.
(CVE-2018-20783)
It was discovered that PHP incorrectly handled certain files. An attacker
could possibly use this issue to access sensitive information or possibly
cause a crash, resulting in a denial of service. (CVE-2019-11036)
Original advisory details:
It was discovered that PHP incorrectly handled memory when unserializing
certain data. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service,
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2018-03-19·CVSS 7.5
CVE-2016-10712 [HIGH] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
It was discovered that PHP incorrectly handled certain stream metadata. A
remote attacker could possibly use this issue to set arbitrary metadata.
This issue only affected Ubuntu 14.04 LTS. (CVE-2016-10712)
It was discovered that PHP incorrectly handled the PHAR 404 error page. A
remote attacker could possibly use this issue to conduct cross-site
scripting (XSS) attacks. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 17.10. (CVE-2018-5712)
It was discovered that PHP incorrectly handled parsing certain HTTP
responses. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2018-7584)
Instructions: In Ubuntu 16.04 LTS and U
Red Hat
php: Output of stream_get_meta_data can be falsified by its input
vendor_redhat·2016-01-10·CVSS 7.5
CVE-2016-10712 [HIGH] CWE-20 php: Output of stream_get_meta_data can be falsified by its input
php: Output of stream_get_meta_data can be falsified by its input
In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = stream_get_meta_data(fopen($file, "r"))['uri']" call mishandles the case where $file is data:text/plain;uri=eviluri, -- in other words, metadata can be set by an attacker.
Package: php (Red Hat Enterprise Linux 5) - Will not fix
Package: php53 (Red Hat Enterprise Linux 5) - Will not fix
Package: php (Red Hat Enterprise Linux 6) - Will not fix
Package: php (Red Hat Enterprise Linux 7) - Will not fix
Package: php54-php (Red Hat Software Collections) - Will not fix
Package: php55-php (Red Hat Software Collecti
No detection rules found.
No public exploits indexed.
https://bugs.php.net/bug.php?id=71323https://git.php.net/?p=php-src.git%3Ba=commit%3Bh=6297a117d77fa3a0df2e21ca926a92c231819cd5https://usn.ubuntu.com/3566-2/https://usn.ubuntu.com/3600-1/https://bugs.php.net/bug.php?id=71323https://git.php.net/?p=php-src.git%3Ba=commit%3Bh=6297a117d77fa3a0df2e21ca926a92c231819cd5https://usn.ubuntu.com/3566-2/https://usn.ubuntu.com/3600-1/
2018-02-09
Published