The JSST and the Joomla! Security Center report:
[20151206] - Core - Session Hardening
The Joomla Security Strike team has been following up on the
critical security vulnerability patched last week. Since the recent
update it has become clear that the root cause is a bug in PHP
itself. This was fixed by PHP in September of 2015 with the releases
of PHP 5.4.45, 5.5.29, 5.6.13 (Note that this is fixed in all
versions of PHP 7 and has been back-ported in some specific Linux
LTS versions of PHP 5.3). This fixes the bug across all supported
PHP versions.
[20151207] - Core - SQL Injection
Inadequate filtering of request data leads to a SQL Injection
vulnerability.