Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2008-3661

Published: 23 September 2008

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

Notes

AuthorNote
mdeslaur
Drupal doesn't consider this an issue.
"It's your responsibility to set session.cookie_secure in the
SSL virtual host if you want an SSL-only website."
setting to "ignored"

Priority

Low

Status

Package Release Status
drupal
Launchpad, Ubuntu, Debian
dapper Ignored

feisty Ignored
(end of life, was needs-triage)
gutsy Does not exist

hardy Does not exist

intrepid Does not exist

jaunty Does not exist

upstream Ignored

drupal5
Launchpad, Ubuntu, Debian
dapper Does not exist

feisty Does not exist

gutsy Ignored
(end of life, was needs-triage)
hardy Ignored

intrepid Ignored

jaunty Ignored

upstream Ignored