CVE-2008-3663 Cookies for SSL connection could be sent over non-SSL

Bug #328938 reported by Andreas Wenning
256
Affects Status Importance Assigned to Milestone
squirrelmail (Ubuntu)
Fix Released
Undecided
Unassigned
Dapper
Fix Released
Undecided
Unassigned
Gutsy
Fix Released
Undecided
Unassigned
Hardy
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: squirrelmail

=== Official description ===
An issue was fixed that allowed the cookies of a session started
over SSL (https) to be transmitted over HTTP aswell. This affects
installations that offer SquirrelMail both over HTTP and HTTPS.
This is known as setting the "secure" flag of the cookie.

An override option has been added that can be used when you have
a need to continue a session over HTTP that has been started over
HTTPS, although we do not recommend that.

=== Further info ===
http://www.squirrelmail.org/security/issue/2008-09-28

=== Affects ===
jaunty: already fixed (from debian)
intrepid: already fixed (from debian)
hardy: affected
gutsy: affected
dapper: affected
dapper/backports: affected; new backport from gutsy should be made after this has been fixed

=== More info ===
The debdiffs for gutsy and dapper contains the patch for CVE-2008-2379 (see bug 306536) as well.

Revision history for this message
Andreas Wenning (andreas-wenning) wrote :

squirrelmail (2:1.4.13-2ubuntu1.2) hardy-security; urgency=low

  * SECURITY UPDATE: Cookies sent over HTTPS will now be confined to
    HTTPS only (cookie secure flag) and more support for the HTTPOnly
    cookie attribute. Patch taken from upstream release. (LP: #328938)
    - CVE-2008-3663
    - http://www.squirrelmail.org/security/issue/2008-09-28

Revision history for this message
Andreas Wenning (andreas-wenning) wrote :

squirrelmail (2:1.4.10a-2ubuntu0.1) gutsy-security; urgency=low

  * SECURITY UPDATE: cross site scripting issue in the HTML filter.
    Patch taken from upstream release. (LP: #306536)
    - CVE-2008-2379
    - http://www.squirrelmail.org/security/issue/2008-12-04
  * SECURITY UPDATE: Cookies sent over HTTPS will now be confined to
    HTTPS only (cookie secure flag) and more support for the HTTPOnly
    cookie attribute. Patch taken from upstream release. (LP: #328938)
    - CVE-2008-3663
    - http://www.squirrelmail.org/security/issue/2008-09-28

Revision history for this message
Andreas Wenning (andreas-wenning) wrote :

squirrelmail (2:1.4.6-1ubuntu0.2) dapper-security; urgency=low

  * SECURITY UPDATE: cross site scripting issue in the HTML filter.
    Patch taken from upstream release. (LP: #306536)
    - CVE-2008-2379
    - http://www.squirrelmail.org/security/issue/2008-12-04
  * SECURITY UPDATE: Cookies sent over HTTPS will now be confined to
    HTTPS only (cookie secure flag) and more support for the HTTPOnly
    cookie attribute. Patch taken from upstream release. (LP: #328938)
    - CVE-2008-3663
    - http://www.squirrelmail.org/security/issue/2008-09-28

Revision history for this message
Kees Cook (kees) wrote :

Thank you for the debdiffs! I have set the bug to "In Progress" so that we will notice them when doing patch review. Have you tested each of the patches you created that they both build and operate correctly for each release?

Changed in squirrelmail (Ubuntu Hardy):
status: New → In Progress
Changed in squirrelmail (Ubuntu Gutsy):
status: New → In Progress
Changed in squirrelmail (Ubuntu Dapper):
status: New → In Progress
Changed in squirrelmail (Ubuntu):
status: New → Fix Released
Revision history for this message
Andreas Wenning (andreas-wenning) wrote :

All the above debdiffs has been both build and tested that they work on each release in question.

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for the debdiffs Andreas.

I'm preparing packages for gutsy and hardy now.

For dapper, it seems the debdiff is missing. It looks like the gutsy one got uploaded twice by mistake.

Could you please re-attach it?

Also, our cve tracker says dapper may still be vulnerable to CVE-2006-3174 and CVE-2006-3665. Is this something you've looked at?

Thanks!

Changed in squirrelmail:
status: In Progress → Fix Committed
status: In Progress → Fix Committed
assignee: nobody → mdeslaur
status: In Progress → Incomplete
Revision history for this message
Andreas Wenning (andreas-wenning) wrote :

My mistake; here is the right file.

For CVE-2006-3174 and CVE-2006-3665 they both only occur if using register_globals. The Squirrelmail team defines this as a serious no-go, and will in general not even provide patches for it.

I'll take a look at both of them in any case though.

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks Andreas,

The register_globals requirement explains why I couldn't find any details on the other issues.

I'll build the dapper update with the debdiff you've provided.

Changed in squirrelmail:
assignee: mdeslaur → nobody
status: Incomplete → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package squirrelmail - 2:1.4.10a-2ubuntu0.1

---------------
squirrelmail (2:1.4.10a-2ubuntu0.1) gutsy-security; urgency=low

  * SECURITY UPDATE: cross site scripting issue in the HTML filter.
    Patch taken from upstream release. (LP: #306536)
    - CVE-2008-2379
    - http://www.squirrelmail.org/security/issue/2008-12-04
  * SECURITY UPDATE: Cookies sent over HTTPS will now be confined to
    HTTPS only (cookie secure flag) and more support for the HTTPOnly
    cookie attribute. Patch taken from upstream release. (LP: #328938)
    - CVE-2008-3663
    - http://www.squirrelmail.org/security/issue/2008-09-28

 -- Andreas Wenning <email address hidden> Fri, 13 Feb 2009 08:03:02 +0100

Changed in squirrelmail:
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package squirrelmail - 2:1.4.13-2ubuntu1.2

---------------
squirrelmail (2:1.4.13-2ubuntu1.2) hardy-security; urgency=low

  * SECURITY UPDATE: Cookies sent over HTTPS will now be confined to
    HTTPS only (cookie secure flag) and more support for the HTTPOnly
    cookie attribute. Patch taken from upstream release. (LP: #328938)
    - CVE-2008-3663
    - http://www.squirrelmail.org/security/issue/2008-09-28

 -- Andreas Wenning <email address hidden> Fri, 13 Feb 2009 07:53:14 +0100

Changed in squirrelmail:
status: Fix Committed → Fix Released
Changed in squirrelmail (Ubuntu Dapper):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.