Lucene search

K
redhatcveRedhat.comRH:CVE-2017-7272
HistoryMar 31, 2017 - 9:48 a.m.

CVE-2017-7272

2017-03-3109:48:04
redhat.com
access.redhat.com
21

0.003 Low

EPSS

Percentile

66.0%

PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen will use the port number that is specified in the hostname argument, instead of the port number in the second argument of the function.