[CVE-2007-6077] Potential session fixation attack
Bug #173203 reported by
William Grant
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Ruby on Rails |
Fix Released
|
Unknown
|
|||
rails (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Dapper |
Won't Fix
|
Undecided
|
Unassigned | ||
Edgy |
Won't Fix
|
Undecided
|
Unassigned | ||
Feisty |
Won't Fix
|
Undecided
|
Unassigned | ||
Gutsy |
Fix Released
|
Undecided
|
William Grant | ||
Hardy |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: rails
The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_
Hardy has 1.2.6, so should be fixed.
Related branches
CVE References
Changed in rails: | |
status: | New → Fix Released |
Changed in rails: | |
status: | Unknown → Fix Released |
To post a comment you must log in.
Thanks for preparing this! I've uploaded it to the security queue; it should be published shortly.