Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-3065

Опубликовано: 31 мая 2010
Источник: redhat
CVSS2: 4.3

Описание

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

Отчет

This issue is not planned to be fixed in Red Hat Enterprise Linux 3 due to this product being in Production 3 of its maintenance life-cycle, where only qualified security errata of important and critical impact are addressed. For further information about the Errata Support Policy, visit: http://www.redhat.com/security/updates/errata

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Application Stack v2 for Enterprise LinuxphpAffected
Red Hat Enterprise Linux 3phpAffected
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 4phpFixedRHSA-2010:091929.11.2010
Red Hat Enterprise Linux 5phpFixedRHSA-2010:091929.11.2010

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=619030php: session serializer session data injection vulnerability (MOPS-2010-060)

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 15 лет назад

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

nvd
больше 15 лет назад

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

debian
больше 15 лет назад

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 throu ...

github
больше 3 лет назад

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

oracle-oval
около 15 лет назад

ELSA-2010-0919: php security update (MODERATE)

4.3 Medium

CVSS2