Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-10397

Опубликовано: 10 июл. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.example.com:80#@good.example.com/ and evil.example.com:80?@good.example.com/ inputs to the parse_url function (implemented in the php_url_parse_ex function in ext/standard/url.c).

РелизСтатусПримечание
artful

DNE

devel

DNE

esm-infra-legacy/trusty

released

5.5.9+dfsg-1ubuntu4.22
precise/esm

not-affected

5.3.10-1ubuntu3.28
trusty

released

5.5.9+dfsg-1ubuntu4.22
trusty/esm

released

5.5.9+dfsg-1ubuntu4.22
upstream

released

5.6.28
vivid/ubuntu-core

DNE

xenial

DNE

yakkety

DNE

Показывать по

РелизСтатусПримечание
artful

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra-legacy/xenial

not-affected

7.0.18-0ubuntu0.16.04.1
esm-infra/xenial

not-affected

7.0.18-0ubuntu0.16.04.1
precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

7.0.13
vivid/ubuntu-core

DNE

Показывать по

РелизСтатусПримечание
artful

not-affected

7.1.6-2ubuntu1
devel

not-affected

7.1.6-2ubuntu1
esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

needs-triage

vivid/ubuntu-core

DNE

xenial

DNE

yakkety

DNE

Показывать по

EPSS

Процентиль: 78%
0.01908
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
redhat
почти 10 лет назад

In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.example.com:80#@good.example.com/ and evil.example.com:80?@good.example.com/ inputs to the parse_url function (implemented in the php_url_parse_ex function in ext/standard/url.c).

CVSS3: 7.5
nvd
около 9 лет назад

In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.example.com:80#@good.example.com/ and evil.example.com:80?@good.example.com/ inputs to the parse_url function (implemented in the php_url_parse_ex function in ext/standard/url.c).

CVSS3: 7.5
debian
около 9 лет назад

In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of vari ...

CVSS3: 7.5
github
около 4 лет назад

In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.example.com:80#@good.example.com/ and evil.example.com:80?@good.example.com/ inputs to the parse_url function (implemented in the php_url_parse_ex function in ext/standard/url.c).

CVSS3: 7.5
fstec
около 9 лет назад

Уязвимость функции parse_url интерпретатора языка программирования PHP, позволяющая нарушителю подменить отображаемый URL

EPSS

Процентиль: 78%
0.01908
Низкий

5 Medium

CVSS2

7.5 High

CVSS3