{"id":"UBUNTU-CVE-2016-7398","details":"A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.","modified":"2026-04-22T10:56:43.712382Z","published":"2019-09-06T19:15:00Z","upstream":["CVE-2016-7398"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2016-7398"},{"type":"REPORT","url":"https://bugs.php.net/bug.php?id=73055"},{"type":"REPORT","url":"https://bugs.php.net/bug.php?id=73055&edit=1"},{"type":"REPORT","url":"https://github.com/m6w6/ext-http/commit/17137d4ab1ce81a2cee0fae842340a344ef3da83"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2016-7398"}],"affected":[{"package":{"name":"php-pecl-http","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/php-pecl-http@3.0.1-0ubuntu5?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.4-1build1","3.0.1-0ubuntu2","3.0.1-0ubuntu3","3.0.1-0ubuntu4","3.0.1-0ubuntu5"],"ecosystem_specific":{"binaries":[{"binary_name":"php-pecl-http","binary_version":"3.0.1-0ubuntu5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-7398.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}