LWN.net Logo

squirrelmail: session hijacking vulnerability

Package(s):squirrelmail CVE #(s):CVE-2008-3663
Created:October 23, 2008 Updated:May 13, 2009
Description: squirrelmail is vulnerable to session hijacking. From the Red Hat bug report:

Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

Alerts:
Mandriva MDVSA-2009:053 2009-02-24
SuSE SUSE-SR:2009:004 2009-02-17
CentOS CESA-2009:0010 2009-01-12
Red Hat RHSA-2009:0010-01 2009-01-12
SuSE SUSE-SR:2008:028 2008-12-16
Fedora FEDORA-2008-9071 2008-10-24
Fedora FEDORA-2008-8559 2008-10-23

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds