|
|
| |
|
| |
squirrelmail: session handling flaw
| Package(s): | squirrelmail |
CVE #(s): | CVE-2009-0030
|
| Created: | January 20, 2009 |
Updated: | February 17, 2009 |
| Description: |
From the Red Hat advisory: The Red Hat SquirrelMail packages provided by the RHSA-2009:0010 advisory introduced a session handling flaw. Users who logged back into SquirrelMail without restarting their web browsers were assigned fixed session identifiers. A remote attacker could make use of that flaw to hijack user sessions.
|
| Alerts: |
|
( Log in to post comments)
|
|
|