Req #60491 [Csd]: Session module is adoptive

From: Date: Wed, 07 Jan 2015 00:48:39 +0000
Subject: Req #60491 [Csd]: Session module is adoptive
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189695@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=60491&edit=1 ID: 60491 Updated by: yohgaki@php.net Reported by: yohgaki@php.net Summary: Session module is adoptive Status: Closed Type: Feature/Change Request Package: Session related Operating System: All PHP Version: Irrelevant Assigned To: yohgaki Block user comment: N Private report: N CVE-ID: 2011-4718 New Comment: For the record, this issue can be avoided by calling session_regenerate_id() properly. e.g. Regenerate session ID upon login/when item is put in cart at first time, etc. With use_strict_mode=On, programmer does not have to care for adoptive session manager. When use_strict_mode=Off, programmer must care for adoptive session manager. Previous Comments: ------------------------------------------------------------------------ [2014-12-30 02:05:08] yqbjtu at 163 dot com is PHP5.4 affected by this CVE-2011-4718? I see it is fixed in 5.5.2. but how about the php 5.4 serials, such as the latest php 5.4.36? Thank you! ------------------------------------------------------------------------ [2014-02-25 05:00:54] yohgaki@php.net This is closed. Use use_strict_mode=on. ------------------------------------------------------------------------ [2014-02-25 01:24:42] johannes@php.net yasuo-san, please confirm this can be closed (and marked public). ------------------------------------------------------------------------ [2014-02-12 17:15:41] tyrael@php.net this should be closed, as it is fixed since 5.5.2 with the addition of the strict sessions, right? ------------------------------------------------------------------------ [2011-12-10 00:52:07] yohgaki@php.net Description: ------------ Session module is adoptive, so there are chances for session fixation due to adoption. CVE ID: CVE-2011-4718 https://wiki.php.net/rfc/strict_sessions ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=60491&edit=1

« previous php.bugs (#189695) next »