PHP Improper Input Validation Vulnerability - CVE-2017-7189 - Vulnerability Database

PHP Improper Input Validation Vulnerability - CVE-2017-7189

High
Reference: CVE-2017-7189
Title: PHP Improper Input Validation Vulnerability
Overview:

main/streams/xp_socket.c in PHP 7.x before 2017-03-07 misparses fsockopen calls such as by interpreting fsockopen(39127.0.0.1:8039 443) as if the address/port were 127.0.0.1:80:443 which is later truncated to 127.0.0.1:80. This behavior has a security risk if the explicitly provided port number (i.e. 443 in this example) is hardcoded into an application as a security policy but the hostname argument (i.e. 127.0.0.1:80 in this example) is obtained from untrusted input.