A type confusion vulnerability in the mergeparam() function of phphttp_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.
[
{
"source": "https://github.com/m6w6/ext-http/commit/17137d4ab1ce81a2cee0fae842340a344ef3da83",
"signature_type": "Line",
"id": "CVE-2016-7398-1d33e960",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"131021496443385898743292904032294007741",
"91232038910744409217388444223265266793",
"261318667876175873601489787703585171531",
"167123906585228430315616853570800366652"
]
},
"target": {
"file": "src/php_http_params.c"
},
"deprecated": false
}
]