CVE-2016-10712: Input Validation
In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all o ...
Other sources
It was found that phpstreampopulatemetadata is not restricted to writing into fields that are not already set, instead phpstream with ops set to phpstreamtempops fills the metadata with whatever the user supplies.
Upstream bug:
https://bugs.php.net/bug.php?id=71323
Upstream patch:
https://git.php.net/?p=php-src.git;a=commit;h=6297a117d77fa3a0df2e21ca926a92c231819cd5
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 5.6.18 - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 5.5.32 - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 5.5.32 - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 5.6.18 - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 7.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10712?
The severity of CVE-2016-10712 is high (7.5).
How does CVE-2016-10712 affect PHP?
CVE-2016-10712 affects PHP versions before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3.
What is the impact of CVE-2016-10712?
The impact of CVE-2016-10712 is that all return values of stream_get_meta_data can be controlled if the input can be controlled.
Are there any available remedies for CVE-2016-10712?
There are no available remedies for CVE-2016-10712 according to the provided information.
Where can I find more information about CVE-2016-10712?
You can find more information about CVE-2016-10712 at the following references: [1](https://bugs.php.net/bug.php?id=71323), [2](https://git.php.net/?p=php-src.git;a=commit;h=6297a117d77fa3a0df2e21ca926a92c231819cd5), [3](https://usn.ubuntu.com/3600-1/).