Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 253483 (CVE-2008-4122) - www-apps/joomla < 1.5.9: secure cookie flag not set (CVE-2008-4122)
Summary: www-apps/joomla < 1.5.9: secure cookie flag not set (CVE-2008-4122)
Status: RESOLVED FIXED
Alias: CVE-2008-4122
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-01-02 21:49 UTC by Stefan Behte (RETIRED)
Modified: 2009-01-26 19:13 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2009-01-02 21:49:31 UTC
CVE-2008-4122 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4122):
  Joomla! 1.5.8 does not set the secure flag for the session cookie in
  an https session, which makes it easier for remote attackers to
  capture this cookie by intercepting its transmission within an http
  session.
Comment 1 Peter Volkov (RETIRED) gentoo-dev 2009-01-26 18:41:53 UTC
New version (1.5.9) was just added to the tree. Ebuild is ~arch, and package.masked, so bug can be closed.
Comment 2 Christian Hoffmann (RETIRED) gentoo-dev 2009-01-26 19:13:50 UTC
Yep... doing so.