Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2008-3663 | First vendor Publication | 2008-09-24 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3663 |
CAPEC : Common Attack Pattern Enumeration & Classification
Id | Name |
---|---|
CAPEC-102 | Session Sidejacking |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-310 | Cryptographic Issues |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:10548 | |||
Oval ID: | oval:org.mitre.oval:def:10548 | ||
Title: | Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. | ||
Description: | Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2008-3663 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:22370 | |||
Oval ID: | oval:org.mitre.oval:def:22370 | ||
Title: | ELSA-2009:0010: squirrelmail security update (Moderate) | ||
Description: | Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2009:0010-01 CVE-2008-2379 CVE-2008-3663 | Version: | 13 |
Platform(s): | Oracle Linux 5 | Product(s): | squirrelmail |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:29372 | |||
Oval ID: | oval:org.mitre.oval:def:29372 | ||
Title: | RHSA-2009:0010 -- squirrelmail security update (Moderate) | ||
Description: | An updated squirrelmail package that resolves various security issues is now available for Red Hat Enterprise Linux 3, 4 and 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. SquirrelMail is an easy-to-configure, standards-based, webmail package written in PHP. It includes built-in PHP support for the IMAP and SMTP protocols, and pure HTML 4.0 page-rendering (with no JavaScript required) for maximum browser-compatibility, strong MIME support, address books, and folder manipulation. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2009:0010 CESA-2009:0010-CentOS 3 CESA-2009:0010-CentOS 5 CVE-2008-2379 CVE-2008-3663 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 3 CentOS Linux 5 | Product(s): | squirrelmail |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2011-08-09 | Name : CentOS Update for squirrelmail CESA-2009:0057 centos5 i386 File : nvt/gb_CESA-2009_0057_squirrelmail_centos5_i386.nasl |
2011-08-09 | Name : CentOS Update for squirrelmail CESA-2009:0057 centos4 i386 File : nvt/gb_CESA-2009_0057_squirrelmail_centos4_i386.nasl |
2011-08-09 | Name : CentOS Update for squirrelmail CESA-2009:0057 centos3 i386 File : nvt/gb_CESA-2009_0057_squirrelmail_centos3_i386.nasl |
2011-08-09 | Name : CentOS Update for squirrelmail CESA-2009:0010 centos3 i386 File : nvt/gb_CESA-2009_0010_squirrelmail_centos3_i386.nasl |
2011-08-09 | Name : CentOS Update for squirrelmail CESA-2009:0010 centos4 i386 File : nvt/gb_CESA-2009_0010_squirrelmail_centos4_i386.nasl |
2011-08-09 | Name : CentOS Update for squirrelmail CESA-2009:0010 centos5 i386 File : nvt/gb_CESA-2009_0010_squirrelmail_centos5_i386.nasl |
2010-05-12 | Name : Mac OS X Security Update 2009-001 File : nvt/macosx_secupd_2009-001.nasl |
2009-06-05 | Name : Ubuntu USN-723-1 (git-core) File : nvt/ubuntu_723_1.nasl |
2009-06-05 | Name : Fedora Core 9 FEDORA-2009-5471 (squirrelmail) File : nvt/fcore_2009_5471.nasl |
2009-05-20 | Name : Fedora Core 9 FEDORA-2009-4870 (squirrelmail) File : nvt/fcore_2009_4870.nasl |
2009-03-02 | Name : Mandrake Security Advisory MDVSA-2009:053 (squirrelmail) File : nvt/mdksa_2009_053.nasl |
2009-02-18 | Name : SuSE Security Summary SUSE-SR:2009:004 File : nvt/suse_sr_2009_004.nasl |
2009-02-17 | Name : Fedora Update for squirrelmail FEDORA-2008-8559 File : nvt/gb_fedora_2008_8559_squirrelmail_fc9.nasl |
2009-02-17 | Name : Fedora Update for squirrelmail FEDORA-2008-9071 File : nvt/gb_fedora_2008_9071_squirrelmail_fc8.nasl |
2009-02-16 | Name : Fedora Update for squirrelmail FEDORA-2008-10740 File : nvt/gb_fedora_2008_10740_squirrelmail_fc9.nasl |
2009-02-16 | Name : Fedora Update for squirrelmail FEDORA-2008-10918 File : nvt/gb_fedora_2008_10918_squirrelmail_fc8.nasl |
2009-01-20 | Name : RedHat Security Advisory RHSA-2009:0057 File : nvt/RHSA_2009_0057.nasl |
2009-01-13 | Name : CentOS Security Advisory CESA-2009:0010 (squirrelmail) File : nvt/ovcesa2009_0010.nasl |
2009-01-13 | Name : RedHat Security Advisory RHSA-2009:0010 File : nvt/RHSA_2009_0010.nasl |
2008-09-24 | Name : FreeBSD Ports: squirrelmail File : nvt/freebsd_squirrelmail5.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
49095 | SquirrelMail HTTPS Session Cookie Secure Flag Weakness |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-07-12 | Name : The remote Oracle Linux host is missing a security update. File : oraclelinux_ELSA-2009-0057.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing a security update. File : oraclelinux_ELSA-2009-0010.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing a security update. File : sl_20090119_squirrelmail_on_SL3_x.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing a security update. File : sl_20090112_squirrelmail_on_SL3_x.nasl - Type : ACT_GATHER_INFO |
2009-05-26 | Name : The remote Fedora host is missing a security update. File : fedora_2009-5471.nasl - Type : ACT_GATHER_INFO |
2009-05-13 | Name : The remote Fedora host is missing a security update. File : fedora_2009-4870.nasl - Type : ACT_GATHER_INFO |
2009-02-13 | Name : The remote host is missing a Mac OS X update that fixes various security issues. File : macosx_SecUpd2009-001.nasl - Type : ACT_GATHER_INFO |
2009-02-12 | Name : The remote web server contains a PHP application that handles session cookies... File : squirrelmail_insecure_https_cookie.nasl - Type : ACT_GATHER_INFO |
2009-02-05 | Name : The remote openSUSE host is missing a security update. File : suse_squirrelmail-5978.nasl - Type : ACT_GATHER_INFO |
2009-01-20 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2009-0057.nasl - Type : ACT_GATHER_INFO |
2009-01-20 | Name : The remote CentOS host is missing a security update. File : centos_RHSA-2009-0057.nasl - Type : ACT_GATHER_INFO |
2009-01-13 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2009-0010.nasl - Type : ACT_GATHER_INFO |
2009-01-13 | Name : The remote CentOS host is missing a security update. File : centos_RHSA-2009-0010.nasl - Type : ACT_GATHER_INFO |
2008-11-21 | Name : The remote openSUSE host is missing a security update. File : suse_squirrelmail-5792.nasl - Type : ACT_GATHER_INFO |
2008-11-18 | Name : The remote openSUSE host is missing a security update. File : suse_squirrelmail-5778.nasl - Type : ACT_GATHER_INFO |
2008-10-27 | Name : The remote Fedora host is missing a security update. File : fedora_2008-9071.nasl - Type : ACT_GATHER_INFO |
2008-10-24 | Name : The remote Fedora host is missing a security update. File : fedora_2008-8559.nasl - Type : ACT_GATHER_INFO |
2008-09-24 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_a0afb4b989a111dda65b00163e000016.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:13:27 |
|
2024-11-28 12:16:18 |
|
2021-05-04 12:07:55 |
|
2021-04-22 01:08:17 |
|
2020-05-23 00:22:07 |
|
2018-10-12 00:20:26 |
|
2017-09-29 09:23:41 |
|
2017-08-08 09:24:19 |
|
2016-04-26 17:44:31 |
|
2014-02-17 10:46:07 |
|
2013-05-11 00:23:51 |
|