CVE-2006-4244

Publication date 31 August 2006

Last updated 24 July 2024


Ubuntu priority

SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie and the parameter to the same value.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
sql-ledger 9.10 karmic
Fixed 2.6.19-1
9.04 jaunty
Fixed 2.6.19-1
8.10 intrepid
Fixed 2.6.19-1
8.04 LTS hardy
Fixed 2.6.19-1
7.10 gutsy
Fixed 2.6.19-1
7.04 feisty
Fixed 2.6.19-1
6.10 edgy
Fixed 2.6.19-1
6.06 LTS dapper Ignored end of life