Comment 1 for bug 328938

Revision history for this message
Andreas Wenning (andreas-wenning) wrote :

squirrelmail (2:1.4.13-2ubuntu1.2) hardy-security; urgency=low

  * SECURITY UPDATE: Cookies sent over HTTPS will now be confined to
    HTTPS only (cookie secure flag) and more support for the HTTPOnly
    cookie attribute. Patch taken from upstream release. (LP: #328938)
    - CVE-2008-3663
    - http://www.squirrelmail.org/security/issue/2008-09-28