Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHP Session_Regenerate_ID Function Double Free Memory Corruption Vulnerability

PHP is prone to a double-free memory-corruption vulnerability.

Attackers may be able to exploit this issue to execute arbitrary code in the context of the webserver process or to cause denial-of-service conditions.

This issue is proven to be locally exploitable. Remote attack vectors may also be possible, but this is yet to be confirmed.

This issue affects PHP 5 to 5.2.1. Note that PHP 4 is vulnerable only if successful remote exploits are proven.







 

Privacy Statement
Copyright 2009, SecurityFocus