CVE Database
/

CVE-2016-10712

Back to search

CVE-2016-10712

Published: Feb 9, 2018

Modified: Aug 6, 2024

PUBLISHED

Description

In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = stream_get_meta_data(fopen($file, "r"))['uri']" call mishandles the case where $file is data:text/plain;uri=eviluri, -- in other words, metadata can be set by an attacker.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-3600-1
vendor-advisory
x_refsource_UBUNTU
USN-3566-2
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now