// For flags

CVE-2016-10397

Ubuntu Security Notice USN-3382-2

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.example.com:80#@good.example.com/ and evil.example.com:80?@good.example.com/ inputs to the parse_url function (implemented in the php_url_parse_ex function in ext/standard/url.c).

En PHP, en versiones anteriores a la 5.6.28 y en versiones 7.x anteriores a la 7.0.13, la manipulación incorrecta de varios componentes URI en el analizador sintáctico de URI podría ser empleada por atacantes para omitir comprobaciones URI específicas de hostname, tal y como demuestran las entradas evil.example.com:80#@good.example.com/ y evil.example.com:80?@good.example.com/ en la función parse_url (implementadas en la función php_url_parse_ex en ext/standard/url.c).

It was discovered that the PHP opcache created keys for files it cached based on their filepath. A local attacker could possibly use this issue in a shared hosting environment to obtain sensitive information. This issue only affected Ubuntu 14.04 LTS. It was discovered that the PHP URL parser incorrectly handled certain URI components. A remote attacker could possibly use this issue to bypass hostname-specific URL checks. This issue only affected Ubuntu 14.04 LTS. Various other issues were also addressed.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-07-10 CVE Reserved
  • 2017-07-10 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
<= 5.6.27
Search vendor "Php" for product "Php" and version " <= 5.6.27"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
7.0.0
Search vendor "Php" for product "Php" and version "7.0.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
7.0.1
Search vendor "Php" for product "Php" and version "7.0.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
7.0.2
Search vendor "Php" for product "Php" and version "7.0.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
7.0.3
Search vendor "Php" for product "Php" and version "7.0.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
7.0.4
Search vendor "Php" for product "Php" and version "7.0.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
7.0.5
Search vendor "Php" for product "Php" and version "7.0.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
7.0.6
Search vendor "Php" for product "Php" and version "7.0.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
7.0.7
Search vendor "Php" for product "Php" and version "7.0.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
7.0.8
Search vendor "Php" for product "Php" and version "7.0.8"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
7.0.9
Search vendor "Php" for product "Php" and version "7.0.9"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
7.0.10
Search vendor "Php" for product "Php" and version "7.0.10"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
7.0.11
Search vendor "Php" for product "Php" and version "7.0.11"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
7.0.12
Search vendor "Php" for product "Php" and version "7.0.12"
-
Affected