CVE-2016-7398

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:ext-http:*:*:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:*:*:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:3.1.0:beta1:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:2.6.0:beta2:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:2.6.0:beta1:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:3.1.0:beta2:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:2.6.0:-:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:2.6.0:rc1:*:*:*:*:*:*
cpe:2.3:a:php:ext-http:3.1.0:rc1:*:*:*:*:*:*

Information

Published : 2019-09-06 12:15

Updated : 2019-09-20 14:15


NVD link : CVE-2016-7398

Mitre link : CVE-2016-7398


JSON object : View

CWE
CWE-704

Incorrect Type Conversion or Cast

Advertisement

dedicated server usa

Products Affected

php

  • ext-http