---
title: "CVE-2006-3016\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-3016?format=md
keywords: index, follow
---

# CVE-2006-3016

Publication date 14 June 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Unspecified vulnerability in session.c in PHP before 5.1.3 has unknown
impact and attack vectors, related to "certain characters in session
names," including special characters that are frequently associated with
CRLF injection, SQL injection, cross-site scripting (XSS), and HTTP
response splitting vulnerabilities. NOTE: while the nature of the
vulnerability is unspecified, it is likely that this is related to a
violation of an expectation by PHP applications that the session name is
alphanumeric, as implied in the PHP manual for session\_name().

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| php5 | 7.04 feisty | Not affected |
| 6.10 edgy | Not affected |
| 6.06 LTS dapper | Fixed 5.1.2-1ubuntu3.9 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3016)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-3016)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-3016)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-3016)

### Related Ubuntu Security Notices (USN)

+ [USN-320-1](https://usn.ubuntu.com/USN-320-1)
+ PHP vulnerabilities
+ 19 July 2006

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-3016>
