<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>239054</bug_id>
          <alias>CVE-2008-3663</alias>
          <creation_ts>2008-09-29 14:51 0000</creation_ts>
          <short_desc>mail-client/squirrelmail &lt;1.4.16 Insecure cookie session hijacking (CVE-2008-3663)</short_desc>
          <delta_ts>2008-11-26 22:19:28 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.squirrelmail.org/</bug_file_loc>
          <status_whiteboard>B4 [noglsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>rbu@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>eradicator@gentoo.org</cc>
    
    <cc>net-mail@gentoo.org</cc>
    
    <cc>tv@rz-zw.fh-kl.de</cc>

      

      
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-09-29 14:51:32 0000</bug_when>
            <thetext>CVE-2008-3663 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3663):
  Squirrelmail 1.4.15 does not set the secure flag for the session
  cookie in an https session, which can cause the cookie to be sent in
  http requests and make it easier for remote attackers to capture this
  cookie.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-09-29 15:08:53 0000</bug_when>
            <thetext>ANNOUNCE: SquirrelMail 1.4.16 Released
Sep 28, 2008 by Thijs Kinkhorst
 	
The SquirrelMail team is happy to announce the release 1.4.16. The most notable change is that cookies are now sent with the secure attribute set for HTTPS-connections, meaning that they cannot leak to an HTTP-connection on the same SquirrelMail installation. For details see the included ReleaseNotes. We advise users that offer their SquirrelMail both over HTTP and HTTPS to upgrade.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2008-10-01 19:00:22 0000</bug_when>
            <thetext>1.4.16 in CVS.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2008-10-27 19:28:28 0000</bug_when>
            <thetext>(In reply to comment #2)
&gt; 1.4.16 in CVS.
&gt; 

*ping*</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-10-27 20:19:06 0000</bug_when>
            <thetext>Arches, please test and mark stable:
=mail-client/squirrelmail-1.4.16
Target keywords : &quot;alpha amd64 ppc ppc64 sparc x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ranger@gentoo.org</who>
            <bug_when>2008-10-28 00:19:49 0000</bug_when>
            <thetext>ppc64 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rich0@gentoo.org</who>
            <bug_when>2008-10-29 02:00:35 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2008-10-29 22:15:10 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-10-30 10:30:34 0000</bug_when>
            <thetext>alpha/sparc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2008-10-30 19:16:21 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>keytoaster@gentoo.org</who>
            <bug_when>2008-10-31 21:34:08 0000</bug_when>
            <thetext>Ready for vote, I vote YES.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-11-26 18:49:15 0000</bug_when>
            <thetext>I vote NO on this bug. It&apos;s not worse than any of your XSS issues, allowing for compromise of credentials when visiting a malicious link -- and more so, only if someone can tap your link.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-11-26 22:19:28 0000</bug_when>
            <thetext>no too and closing.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>