CVE-2016-7398
06.09.2019, 19:15
A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.Enginsight
Vendor | Product | Version |
---|---|---|
php | ext-http | 𝑥 ≤ 2.5.6 |
php | ext-http | 3.0.0 ≤ 𝑥 ≤ 3.0.1 |
php | ext-http | 2.6.0 |
php | ext-http | 2.6.0:beta1 |
php | ext-http | 2.6.0:beta2 |
php | ext-http | 2.6.0:rc1 |
php | ext-http | 3.1.0 |
php | ext-http | 3.1.0:beta1 |
php | ext-http | 3.1.0:beta2 |
php | ext-http | 3.1.0:rc1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References