CVE-2017-7272
27.03.2017, 17:59
PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen will use the port number that is specified in the hostname argument, instead of the port number in the second argument of the function.
Vendor | Product | Version |
---|---|---|
php | php | 𝑥 ≤ 7.1.3 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References