~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
PublicDate: 2006-06-14
Candidate: CVE-2006-3016
References:
 http://www.ubuntu.com/usn/usn-320-1
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3016
Description:
 Unspecified vulnerability in session.c in PHP before 5.1.3 has unknown
 impact and attack vectors, related to "certain characters in session
 names," including special characters that are frequently associated with
 CRLF injection, SQL injection, cross-site scripting (XSS), and HTTP
 response splitting vulnerabilities.  NOTE: while the nature of the
 vulnerability is unspecified, it is likely that this is related to a
 violation of an expectation by PHP applications that the session name is
 alphanumeric, as implied in the PHP manual for session_name().
Ubuntu-Description:
Notes:
Bugs:
dapper_php5: released (5.1.2-1ubuntu3.9)
edgy_php5: not-affected
feisty_php5: not-affected
devel_php5: not-affected
upstream_php5: