First published: Mon Jan 23 2017(Updated: )
Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbitrary code via non-printable characters in a URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php Pecl Http | <=3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5873 is classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2016-5873, upgrade the pecl_http extension to version 3.0.1 or later.
CVE-2016-5873 affects systems running pecl_http versions prior to 3.0.1.
The implications of CVE-2016-5873 include the potential for remote attackers to execute arbitrary code on affected systems.
All versions of pecl_http prior to 3.0.1 are impacted by CVE-2016-5873.