Name | CVE-2016-3171 |
Description | Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
drupal7 (PTS) | jessie, jessie (lts) | 7.32-1+deb8u19 | fixed |
stretch (security), stretch (lts), stretch | 7.52-2+deb9u18 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
drupal6 | source | squeeze | (unfixed) | end-of-life | ||
drupal6 | source | (unstable) | (unfixed) | |||
drupal7 | source | (unstable) | (not affected) |
- drupal7 <not-affected> (Only affects Drupal 6)
https://www.drupal.org/SA-CORE-2016-001
https://www.openwall.com/lists/oss-security/2016/02/24/19