
DescriptionPHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension. NOTE: it is possible that this issue is a duplicate of CVE-2006-6383.
Debian Bugs410561, 410995

php5 (PTS)jessie, jessie (lts)5.6.40+dfsg-0+deb8u18fixed

php5source(unstable)5.2.0-9unimportant410561, 410995


we normally don't spend much time on safe_mode and open_basedir
issues, but the because the attack vectors are "unspecified", it
might be harder for us to try and sort out the fixes for this
from the session fixes in CVE-2007-0906 (see there for more info)

