LWN.net Logo

request-tracker: session hijack vulnerability

Package(s):request-tracker CVE #(s):CVE-2009-3585
Created:December 3, 2009 Updated:December 11, 2009
Description: From the Debian alert:

Mikal Gule discovered that request-tracker, an extensible trouble-ticket tracking system, is prone to an attack, where an attacker with access to the same domain can hijack a user's RT session.

Alerts:
Fedora FEDORA-2009-12783 2009-12-07
Fedora FEDORA-2009-12827 2009-12-07
Fedora FEDORA-2009-12817 2009-12-07
Debian DSA-1944-1 2009-12-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds