9.8

CVE-2016-7398

Exploit

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhpExt-http Version <= 2.5.6
PhpExt-http Version >= 3.0.0 <= 3.0.1
PhpExt-http Version2.6.0 Update-
PhpExt-http Version2.6.0 Updatebeta1
PhpExt-http Version2.6.0 Updatebeta2
PhpExt-http Version2.6.0 Updaterc1
PhpExt-http Version3.1.0
PhpExt-http Version3.1.0 Updatebeta1
PhpExt-http Version3.1.0 Updatebeta2
PhpExt-http Version3.1.0 Updaterc1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.72% 0.9
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-704 Incorrect Type Conversion or Cast

The product does not correctly convert an object, resource, or structure from one type to a different type.