---
title: "CVE-2006-4433\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-4433?format=md
keywords: index, follow
---

# CVE-2006-4433

Publication date 29 August 2006

Last updated 24 July 2024

---

Ubuntu priority

**Negligible**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

PHP before 4.4.3 and 5.x before 5.1.4 does not limit the character set of
the session identifier (PHPSESSID) for third party session handlers, which
might make it easier for remote attackers to exploit other vulnerabilities
by inserting PHP code into the PHPSESSID, which is stored in the session
file. NOTE: it could be argued that this not a vulnerability in PHP
itself, rather a design limitation that enables certain attacks against
session handlers that do not account for this limitation.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2006-4433?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| php5 | 7.10 gutsy | Not affected |
| 7.04 feisty | Fixed 5.2.1-0ubuntu1.4 |
| 6.10 edgy | Fixed 5.1.6-1ubuntu2.6 |
| 6.06 LTS dapper | Ignored |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [kees](https://launchpad.net/~kees)

this is really an application input sanitization issue

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4433)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-4433)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-4433)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-4433)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-4433>
