10
CVSSv2

CVE-2009-4143

Published: 21/12/2009 Updated: 30/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHP prior to 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.3.11

php php 4.3.4

php php 4.2.3

php php 4.2.2

php php 5.0

php php 4.4.1

php php 4.4.2

php php 5.0.0

php php 2.0b10

php php 2.0

php php 3.0.10

php php 3.0.13

php php 3.0.15

php php 3.0.14

php php 3.0.7

php php 3.0.8

php php 4.0

php php 4.0.7

php php 5.1.2

php php 5.1.3

php php 5.2.2

php php 5.2.3

php php 4.3.10

php php 4.3.5

php php 4.2.0

php php 4.4.5

php php 4.4.6

php php 4.3.7

php php 4.3.8

php php 5.1.0

php php 5.0.5

php php 5.0.1

php php 5

php php 4

php php 3.0

php php 3.0.2

php php 4.3.1

php php 4.3.2

php php 4.1.0

php php 4.2.1

php php 4.4.7

php php 4.3.9

php php 4.4.0

php php 5.0.4

php php 5.0.3

php php 1.0

php php 4.3.3

php php 4.3.6

php php 4.3.0

php php 4.4.3

php php 4.4.4

php php 5.0.2

php php 4.4.8

php php 4.4.9

php php 3.0.12

php php 3.0.1

php php 3.0.17

php php 3.0.16

php php 3.0.5

php php 3.0.6

php php 4.0.6

php php 4.0.5

php php 5.1.4

php php 5.1.5

php php 5.2.4

php php 5.2.5

php php 5.2.6

php php 3.0.11

php php 3.0.18

php php 3.0.4

php php 3.0.3

php php 3.0.9

php php 4.0.0

php php 4.1.2

php php 4.1.1

php php 5.1.1

php php 5.2.1

php php 5.2.10

php php 5.2.9

php php

php php 4.0.1

php php 4.0.4

php php 4.0.3

php php 4.0.2

php php 5.1.6

php php 5.2.0

php php 5.2.7

php php 5.2.8

Vendor Advisories

Maksymilian Arciemowicz discovered that PHP did not properly handle the ini_restore function An attacker could exploit this issue to obtain random memory contents or to cause the PHP server to crash, resulting in a denial of service (CVE-2009-2626) ...
Several remote vulnerabilities have been discovered in PHP 5, an hypertext preprocessor The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-4142 The htmlspecialchars function does not properly handle invalid multi-byte sequences CVE-2009-4143 Memory corruption via session interruption In th ...
Several denial of service vulnerabilities have been discovered in polipo, a small, caching web proxy The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-3305 A malicous remote sever could cause polipo to crash by sending an invalid Cache-Control header CVE-2009-4143 A malicous client could cau ...