CVE-2006-4244
Publication date 31 August 2006
Last updated 24 July 2024
Ubuntu priority
SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie and the parameter to the same value.
Status
Package | Ubuntu Release | Status |
---|---|---|
sql-ledger | 9.10 karmic |
Fixed 2.6.19-1
|
9.04 jaunty |
Fixed 2.6.19-1
|
|
8.10 intrepid |
Fixed 2.6.19-1
|
|
8.04 LTS hardy |
Fixed 2.6.19-1
|
|
7.10 gutsy |
Fixed 2.6.19-1
|
|
7.04 feisty |
Fixed 2.6.19-1
|
|
6.10 edgy |
Fixed 2.6.19-1
|
|
6.06 LTS dapper | Ignored end of life |