CVE-2010-3065

Publication date 20 August 2010

Last updated 24 July 2024


Ubuntu priority

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 10.04 LTS lucid
Fixed 5.3.2-1ubuntu4.5
9.10 karmic
Fixed 5.2.10.dfsg.1-2ubuntu6.5
9.04 jaunty
Fixed 5.2.6.dfsg.1-3ubuntu4.6
8.04 LTS hardy
Fixed 5.2.4-2ubuntu5.12
6.06 LTS dapper
Fixed 5.1.2-1ubuntu3.19

Notes


mdeslaur

This is MOPS-2010-060

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
php5