mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Http_server | Apache | 2.4.1 (including) | 2.4.4 (including) |
Apache2 | Ubuntu | devel | * |
Apache2 | Ubuntu | upstream | * |