CVE-2016-10397: Input Validation
Published Jul 10, 2017
·Updated
In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of vari ...
Affected Software
17 affected components
PHP PHP<=5.6.27
PHP PHP=7.0.0
PHP PHP=7.0.1
PHP PHP=7.0.2
PHP PHP=7.0.3
PHP PHP=7.0.4
PHP PHP=7.0.5
PHP PHP=7.0.6
PHP PHP=7.0.7
PHP PHP=7.0.8
PHP PHP=7.0.9
PHP PHP=7.0.10
PHP PHP=7.0.11
PHP PHP=7.0.12
debian/php5
debian/php7.0
debian/php7.1
Remediation
Patch Available
Event History
Jul 10, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:15 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:14 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2016-10397?
CVE-2016-10397 is a vulnerability in PHP versions before 5.6.28 and 7.x before 7.0.13 that allows attackers to bypass hostname-specific URL checks.
2
Which versions of PHP are affected by CVE-2016-10397?
PHP versions before 5.6.28 and 7.x before 7.0.13 are affected by CVE-2016-10397.
3
What is the severity of CVE-2016-10397?
CVE-2016-10397 has a severity rating of 7.5, which is classified as high.
4
How can an attacker exploit CVE-2016-10397?
An attacker can exploit CVE-2016-10397 by using various URI components in the URL parser to bypass hostname-specific URL checks.
5
Are there any fixes available for CVE-2016-10397?
There are no specific fixes available for CVE-2016-10397, but upgrading to PHP versions 5.6.28 or 7.0.13 (or later) will address the vulnerability.