Description
ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certain hash data structure, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to session deserialization.
Remediation
References
Related Vulnerabilities
PleskWin URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-24044)
WordPress Plugin hashtagger Unspecified Vulnerability (6)
SharePoint CVE-2021-43242 Vulnerability (CVE-2021-43242)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-6660)
Plone CMS Incorrect Default Permissions Vulnerability (CVE-2024-22889)