CVE-2006-0207
Publication date 13 January 2006
Last updated 17 July 2025
Ubuntu priority
Description
Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.
Status
Package | Ubuntu Release | Status |
---|---|---|
php4 | 7.04 feisty | Not in release |
6.10 edgy |
Fixed 4.4.2-1build1
|
|
6.06 LTS dapper |
Fixed 4.4.2-1build1
|
|
php5 | 7.04 feisty |
Fixed 5.2.1-0ubuntu1.4
|
6.10 edgy |
Fixed 5.1.6-1ubuntu2.6
|
|
6.06 LTS dapper |
Fixed 5.1.2-1ubuntu3.9
|