On certain older versions of PHP, user-provided data stored in a Drupal session may be unserialized leading to possible remote code execution.
This issue is mitigated by the fact that it requires an unusual set of circumstances to exploit and depends on the particular Drupal code that is running on the site. It is also believed to be mitigated by upgrading to PHP 5.4.45, 5.5.29, 5.6.13, or any higher version.
Part of security release SA-CORE-2016-001
This vulnerability affects the following application versions:
- Drupal 6.14
- Drupal 6.15
- Drupal 6.16
- Drupal 6.17
- Drupal 6.18
- Drupal 6.19
- Drupal 6.20
- Drupal 6.21
- Drupal 6.22
- Drupal 6.23
- Drupal 6.24
- Drupal 6.25
- Drupal 6.26
- Drupal 6.27
- Drupal 6.28
- Drupal 6.29
- Drupal 6.30
- Drupal 6.31
- Drupal 6.32
- Drupal 6.33
- Drupal 6.34
- Drupal 6.35
- Drupal 6.36
- Drupal 6.37