Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.
Weaknesses in this category are typically found in functionality that processes data. Data processing is the manipulation of input to retrieve or save information.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2016/02/24/19 | mailing list |
http://www.openwall.com/lists/oss-security/2016/03/15/10 | mailing list |
http://www.debian.org/security/2016/dsa-3498 | vendor advisory |
https://www.drupal.org/SA-CORE-2016-001 | patch vendor advisory |