Req #60491 [Csd]: Session module is adoptive
| From: | yohgaki@php.net | Date: | Wed, 07 Jan 2015 00:48:39 +0000 |
| Subject: | Req #60491 [Csd]: Session module is adoptive | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-189695@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=60491&edit=1
ID: 60491
Updated by: yohgaki@php.net
Reported by: yohgaki@php.net
Summary: Session module is adoptive
Status: Closed
Type: Feature/Change Request
Package: Session related
Operating System: All
PHP Version: Irrelevant
Assigned To: yohgaki
Block user comment: N
Private report: N
CVE-ID: 2011-4718
New Comment:
For the record, this issue can be avoided by calling session_regenerate_id() properly. e.g.
Regenerate session ID upon login/when item is put in cart at first time, etc.
With use_strict_mode=On, programmer does not have to care for adoptive session manager. When
use_strict_mode=Off, programmer must care for adoptive session manager.
Previous Comments:
------------------------------------------------------------------------
[2014-12-30 02:05:08] yqbjtu at 163 dot com
is PHP5.4 affected by this CVE-2011-4718? I see it is fixed in 5.5.2. but how about the php 5.4
serials, such as the latest php 5.4.36? Thank you!
------------------------------------------------------------------------
[2014-02-25 05:00:54] yohgaki@php.net
This is closed.
Use use_strict_mode=on.
------------------------------------------------------------------------
[2014-02-25 01:24:42] johannes@php.net
yasuo-san, please confirm this can be closed (and marked public).
------------------------------------------------------------------------
[2014-02-12 17:15:41] tyrael@php.net
this should be closed, as it is fixed since 5.5.2 with the addition of the strict sessions, right?
------------------------------------------------------------------------
[2011-12-10 00:52:07] yohgaki@php.net
Description:
------------
Session module is adoptive, so there are chances for session fixation due to
adoption.
CVE ID: CVE-2011-4718
https://wiki.php.net/rfc/strict_sessions
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=60491&edit=1