CVE-2011-4718

Publication date 13 August 2013

Last updated 24 July 2024


Ubuntu priority

Description

Session fixation vulnerability in the Sessions subsystem in PHP before 5.5.2 allows remote attackers to hijack web sessions by specifying a session ID.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 13.04 raring Ignored end of life
12.10 quantal Ignored end of life
12.04 LTS precise Ignored end of life
10.04 LTS lucid Ignored end of life

Notes


mdeslaur

changes are too intrusive to backport to earlier releases. workarounds are available in upstream wiki.