Beveiligingsadvies

CVE-2016-7398

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-09-06 18:46:53
Laatst bijgewerkt 2024-08-06 01:57:47
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.