PT-2005-4129 · Php · Php

Eric Romang

·

Published

2005-10-27

·

Updated

2018-10-30

·

CVE-2005-3319

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.1.0 and versions 4.4 before 4.4.1
Description The issue allows attackers to cause a denial of service, resulting in a segmentation fault. This can be achieved by manipulating the session.save path option in a .htaccess file or VirtualHost.
Recommendations For versions prior to 5.1.0, update to version 5.1.0 or later to resolve the issue. For version 4.4, update to version 4.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the session.save path option in .htaccess files or VirtualHost configurations until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3319

Affected Products

Php