SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-4143

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

HIGH 10.0EPSS 2.95%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
2.95% probability · 86th percentile
CISA KEV
Not listed
Affected
php/php
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.