Home | Docs | Forums | Lists | Bugs | Planet | Store | GMN | Get Gentoo!
View Bug Activity | Format For Printing | XML | Clone This Bug
CVE-2008-3663 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3663): Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
ANNOUNCE: SquirrelMail 1.4.16 Released Sep 28, 2008 by Thijs Kinkhorst The SquirrelMail team is happy to announce the release 1.4.16. The most notable change is that cookies are now sent with the secure attribute set for HTTPS-connections, meaning that they cannot leak to an HTTP-connection on the same SquirrelMail installation. For details see the included ReleaseNotes. We advise users that offer their SquirrelMail both over HTTP and HTTPS to upgrade.
1.4.16 in CVS.
(In reply to comment #2) > 1.4.16 in CVS. > *ping*
Arches, please test and mark stable: =mail-client/squirrelmail-1.4.16 Target keywords : "alpha amd64 ppc ppc64 sparc x86"
ppc64 done
amd64 stable
x86 stable
alpha/sparc stable
ppc stable
Ready for vote, I vote YES.