UBUNTU-CVE-2016-10712
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-10712
UBUNTU-CVE-2016-10712
Summary:
Details: In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = stream_get_meta_data(fopen($file, "r"))['uri']" call mishandles the case where $file is data:text/plain;uri=eviluri, -- in other words, metadata can be set by an attacker.
References: https://ubuntu.com/security/CVE-2016-10712, https://ubuntu.com/security/notices/USN-3600-1, https://ubuntu.com/security/notices/USN-3566-2, https://www.cve.org/CVERecord?id=CVE-2016-10712
Affected packages
Package
Name: php5
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu4.24?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
