Req #60491 [Csd]: Session module is adoptive
| From: | yohgaki@php.net | Date: | Thu, 08 Jan 2015 06:40:50 +0000 |
| Subject: | Req #60491 [Csd]: Session module is adoptive | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-189727@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=60491&edit=1
ID: 60491
Updated by: yohgaki@php.net
Reported by: yohgaki@php.net
Summary: Session module is adoptive
Status: Closed
Type: Feature/Change Request
Package: Session related
Operating System: All
PHP Version: Irrelevant
Assigned To: yohgaki
Block user comment: N
Private report: N
CVE-ID: 2011-4718
New Comment:
ï¼ liutj
Yes, you are.
If you are using tran_sid, impact is severe. If you are using only cookie, impact is moderate as
typical attack needs JavaScript vulnerability. Note that your colleague may able to set cookie
locally by manipulating browser's cookie database directly. It does not require JavaScript
vulnerability with this method. If you are using http only cookie, risk is relatively low since
JavaScript injection cannot modify session cookie. However, IE had strange cookie priority when I
checked it years ago. HTTP only cookie may not help with IE.
Previous Comments:
------------------------------------------------------------------------
[2015-01-08 02:51:14] liutj at cn dot ibm dot com
Does it means if we never used the method session_regenerate_id(), our product will not be affected
by CVE-2011-4718
------------------------------------------------------------------------
[2015-01-07 00:48:38] yohgaki@php.net
For the record, this issue can be avoided by calling session_regenerate_id() properly. e.g.
Regenerate session ID upon login/when item is put in cart at first time, etc.
With use_strict_mode=On, programmer does not have to care for adoptive session manager. When
use_strict_mode=Off, programmer must care for adoptive session manager.
------------------------------------------------------------------------
[2014-12-30 02:05:08] yqbjtu at 163 dot com
is PHP5.4 affected by this CVE-2011-4718? I see it is fixed in 5.5.2. but how about the php 5.4
serials, such as the latest php 5.4.36? Thank you!
------------------------------------------------------------------------
[2014-02-25 05:00:54] yohgaki@php.net
This is closed.
Use use_strict_mode=on.
------------------------------------------------------------------------
[2014-02-25 01:24:42] johannes@php.net
yasuo-san, please confirm this can be closed (and marked public).
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=60491
--
Edit this bug report at https://bugs.php.net/bug.php?id=60491&edit=1