Req #60491 [Csd]: Session module is adoptive

From: Date: Thu, 08 Jan 2015 06:40:50 +0000
Subject: Req #60491 [Csd]: Session module is adoptive
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189727@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=60491&edit=1 ID: 60491 Updated by: yohgaki@php.net Reported by: yohgaki@php.net Summary: Session module is adoptive Status: Closed Type: Feature/Change Request Package: Session related Operating System: All PHP Version: Irrelevant Assigned To: yohgaki Block user comment: N Private report: N CVE-ID: 2011-4718 New Comment: ï¼ liutj Yes, you are. If you are using tran_sid, impact is severe. If you are using only cookie, impact is moderate as typical attack needs JavaScript vulnerability. Note that your colleague may able to set cookie locally by manipulating browser's cookie database directly. It does not require JavaScript vulnerability with this method. If you are using http only cookie, risk is relatively low since JavaScript injection cannot modify session cookie. However, IE had strange cookie priority when I checked it years ago. HTTP only cookie may not help with IE. Previous Comments: ------------------------------------------------------------------------ [2015-01-08 02:51:14] liutj at cn dot ibm dot com Does it means if we never used the method session_regenerate_id(), our product will not be affected by CVE-2011-4718 ------------------------------------------------------------------------ [2015-01-07 00:48:38] yohgaki@php.net For the record, this issue can be avoided by calling session_regenerate_id() properly. e.g. Regenerate session ID upon login/when item is put in cart at first time, etc. With use_strict_mode=On, programmer does not have to care for adoptive session manager. When use_strict_mode=Off, programmer must care for adoptive session manager. ------------------------------------------------------------------------ [2014-12-30 02:05:08] yqbjtu at 163 dot com is PHP5.4 affected by this CVE-2011-4718? I see it is fixed in 5.5.2. but how about the php 5.4 serials, such as the latest php 5.4.36? Thank you! ------------------------------------------------------------------------ [2014-02-25 05:00:54] yohgaki@php.net This is closed. Use use_strict_mode=on. ------------------------------------------------------------------------ [2014-02-25 01:24:42] johannes@php.net yasuo-san, please confirm this can be closed (and marked public). ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=60491 -- Edit this bug report at https://bugs.php.net/bug.php?id=60491&edit=1

« previous php.bugs (#189727) next »