CVE-2016-5873: Buffer Overflow
Published Jan 23, 2017
·Updated
Buffer overflow in the HTTP URL parsing functions in peclhttp before 3.0.1 might allow remote attackers to execute arbitrary code via non-printable characters in a URL.
Affected Software
1 affected component
PHP Pecl Http<=3.0.1
Remediation
Patch Available
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-5873?
CVE-2016-5873 is classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2016-5873?
To fix CVE-2016-5873, upgrade the pecl_http extension to version 3.0.1 or later.
3
Who is affected by CVE-2016-5873?
CVE-2016-5873 affects systems running pecl_http versions prior to 3.0.1.
4
What are the implications of CVE-2016-5873?
The implications of CVE-2016-5873 include the potential for remote attackers to execute arbitrary code on affected systems.
5
What versions of pecl_http are impacted by CVE-2016-5873?
All versions of pecl_http prior to 3.0.1 are impacted by CVE-2016-5873.