Req #60491 [Com]: Session module is adoptive
| From: | liutj at cn dot ibm dot com | Date: | Thu, 08 Jan 2015 02:51:14 +0000 |
| Subject: | Req #60491 [Com]: Session module is adoptive | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-189725@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=60491&edit=1
ID: 60491
Comment by: liutj at cn dot ibm dot com
Reported by: yohgaki@php.net
Summary: Session module is adoptive
Status: Closed
Type: Feature/Change Request
Package: Session related
Operating System: All
PHP Version: Irrelevant
Assigned To: yohgaki
Block user comment: N
Private report: N
CVE-ID: 2011-4718
New Comment:
Does it means if we never used the method session_regenerate_id(), our product will not be affected
by CVE-2011-4718
Previous Comments:
------------------------------------------------------------------------
[2015-01-07 00:48:38] yohgaki@php.net
For the record, this issue can be avoided by calling session_regenerate_id() properly. e.g.
Regenerate session ID upon login/when item is put in cart at first time, etc.
With use_strict_mode=On, programmer does not have to care for adoptive session manager. When
use_strict_mode=Off, programmer must care for adoptive session manager.
------------------------------------------------------------------------
[2014-12-30 02:05:08] yqbjtu at 163 dot com
is PHP5.4 affected by this CVE-2011-4718? I see it is fixed in 5.5.2. but how about the php 5.4
serials, such as the latest php 5.4.36? Thank you!
------------------------------------------------------------------------
[2014-02-25 05:00:54] yohgaki@php.net
This is closed.
Use use_strict_mode=on.
------------------------------------------------------------------------
[2014-02-25 01:24:42] johannes@php.net
yasuo-san, please confirm this can be closed (and marked public).
------------------------------------------------------------------------
[2014-02-12 17:15:41] tyrael@php.net
this should be closed, as it is fixed since 5.5.2 with the addition of the strict sessions, right?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=60491
--
Edit this bug report at https://bugs.php.net/bug.php?id=60491&edit=1