Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-7398

Опубликовано: 06 сент. 2019
Источник: debian
EPSS Низкий

Описание

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php-pecl-httpfixed3.1.0+2.6.0-1package

Примечания

  • https://bugs.php.net/bug.php?id=73055

  • https://github.com/m6w6/ext-http/commit/17137d4ab1ce81a2cee0fae842340a344ef3da83

EPSS

Процентиль: 90%
0.05723
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

CVSS3: 9.8
nvd
больше 6 лет назад

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

CVSS3: 9.8
github
больше 3 лет назад

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

EPSS

Процентиль: 90%
0.05723
Низкий