Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
|
History
21 Nov 2024, 02:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.debian.org/security/2016/dsa-3498 - | |
References | () http://www.openwall.com/lists/oss-security/2016/02/24/19 - | |
References | () http://www.openwall.com/lists/oss-security/2016/03/15/10 - | |
References | () https://www.drupal.org/SA-CORE-2016-001 - Patch, Vendor Advisory |
Information
Published : 2016-04-12 15:59
Updated : 2024-11-21 02:49
NVD link : CVE-2016-3171
Mitre link : CVE-2016-3171
CVE.ORG link : CVE-2016-3171
JSON object : View
Products Affected
php
- php
debian
- debian_linux
drupal
- drupal
CWE
CWE-19
Data Processing Errors