FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

rt -- Session fixation vulnerability

Affected packages
rt < 3.8.6

Details

VuXML ID 714c1406-e4cf-11de-883a-003048590f9e
Discovery 2009-12-01
Entry 2009-12-09

Secunia reports:

A vulnerability has been reported in RT, which can be exploited by malicious people to conduct session fixation attacks. The vulnerability is caused due to an error in the handling of sessions and can be exploited to hijack another user's session by tricking the user into logging in after following a specially crafted link.

References

Bugtraq ID 37162
CVE Name CVE-2009-3585