Back

HIGH

php: Output of stream_get_meta_data can be falsified by its input

Published Feb 9, 2018

Description

In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = stream_get_meta_data(fopen($file, "r"))['uri']" call mishandles the case where $file is data:text/plain;uri=eviluri, -- in other words, metadata can be set by an attacker.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 9, 2018
Updated Aug 6, 2024
Reserved Feb 9, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jan 10, 2016