CVE-2008-3663
Summary
| CVE | CVE-2008-3663 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-09-24 14:56:52 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Squirrelmail | Squirrelmail | 1.4.15 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SquirrelMail Insecure Cookie Disclosure Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Nabble - squirrelmail-devel - ANNOUNCE: SquirrelMail 1.4.16 Released | af854a3a-2127-422b-91ae-364da2661108 | www.nabble.com | |
| Squirrelmail: Session hijacking vulnerability, CVE-2008-3663 | af854a3a-2127-422b-91ae-364da2661108 | int21.de | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:004 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| About the security content of Security Update 2009-001 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Squirrelmail: Session hijacking vulnerability - SecurityReason.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| APPLE-SA-2009-02-12 Security Update 2009-001 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2008:028 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-01-12 | Tomas Hoger | This issue has been fixed in the affected Red Hat Enterprise Linux versions via: https://rhn.redhat.com/errata/RHSA-2009-0010.html |
There are currently no legacy QID mappings associated with this CVE.