A type confusion vulnerability in the mergeparam() function of phphttp_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.1.0+2.6.0-4build8", "binary_name": "php-http" }, { "binary_version": "3.1.0+2.6.0-4build8", "binary_name": "php-http-dbgsym" }, { "binary_version": "3.1.0+2.6.0-4build8", "binary_name": "php-pecl-http" }, { "binary_version": "3.1.0+2.6.0-4build8", "binary_name": "php-pecl-http-dev" } ] }