CVE-2009-4143: php: $_SESSION usort() interruption corruption

Severity: Critical

CVSS Score: 10

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.