Back

HIGH

php: $_SESSION usort() interruption corruption

Published Dec 21, 2009

Description

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

Affected products

Remediation

Red Hat statement

We do not consider safe_mode / open_basedir restriction bypass issues being security sensitive. For more details see https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1 and https://www.php.net/security-note.php

Metrics

Weaknesses (0)

No CWE recorded.

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 21, 2009
Updated Aug 7, 2024
Reserved Dec 1, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Dec 16, 2009