Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jx2x-3hjr-6vp8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

EPSS

Процентиль: 90%
0.05723
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-704

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

CVSS3: 9.8
nvd
больше 6 лет назад

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

CVSS3: 9.8
debian
больше 6 лет назад

A type confusion vulnerability in the merge_param() function of php_ht ...

EPSS

Процентиль: 90%
0.05723
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-704