Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-3065

Опубликовано: 31 мая 2010
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

Отчет

This issue is not planned to be fixed in Red Hat Enterprise Linux 3 due to this product being in Production 3 of its maintenance life-cycle, where only qualified security errata of important and critical impact are addressed. For further information about the Errata Support Policy, visit: http://www.redhat.com/security/updates/errata

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Application Stack v2 for Enterprise LinuxphpAffected
Red Hat Enterprise Linux 3phpAffected
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 4phpFixedRHSA-2010:091929.11.2010
Red Hat Enterprise Linux 5phpFixedRHSA-2010:091929.11.2010

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=619030php: session serializer session data injection vulnerability (MOPS-2010-060)

EPSS

Процентиль: 63%
0.00455
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 15 лет назад

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

nvd
почти 15 лет назад

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

debian
почти 15 лет назад

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 throu ...

github
около 3 лет назад

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

oracle-oval
больше 14 лет назад

ELSA-2010-0919: php security update (MODERATE)

EPSS

Процентиль: 63%
0.00455
Низкий

4.3 Medium

CVSS2