CVE-2008-3663

Impact:
Moderate
Public Date:
2008-08-12
Bugzilla:
464183: CVE-2008-3663 squirrelmail: session hijacking - secure flag not set for HTTPS-only cookies

The MITRE CVE dictionary describes this issue as:

Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

Find out more about CVE-2008-3663 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue has been fixed in the affected Red Hat Enterprise Linux versions via: https://rhn.redhat.com/errata/RHSA-2009-0010.html

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 5 (squirrelmail) RHSA-2009:0010 2009-01-12
Red Hat Enterprise Linux 4 (squirrelmail) RHSA-2009:0010 2009-01-12
Red Hat Enterprise Linux 3 (squirrelmail) RHSA-2009:0010 2009-01-12

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.