LWN.net Logo

mantis: insecure cookies

Package(s):mantis CVE #(s):CVE-2008-3102
Created:October 21, 2008 Updated:December 2, 2008
Description: From the CVE entry: Mantis 1.1.x through 1.1.2 and 1.2.x through 1.2.0a2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
Alerts:
Gentoo 200812-07 2008-12-02
Fedora FEDORA-2008-9015 2008-10-20
Fedora FEDORA-2008-8925 2008-10-20

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds