X-Git-Url: https://vcs.fsf.org/?p=squirrelmail.git;a=blobdiff_plain;f=doc%2FChangeLog;h=a3a95886bc79ee9e349248fe07d5dbd18e963f3f;hp=730473d639f012e45ad7f47c420b0b56d0e729df;hb=1f80d9f527d2cc2933ee7040aecba908692a20ac;hpb=41afe86f29a37ccf77079acfd0be9c4ef026de55;ds=sidebyside diff --git a/doc/ChangeLog b/doc/ChangeLog index 730473d6..a3a95886 100644 --- a/doc/ChangeLog +++ b/doc/ChangeLog @@ -303,6 +303,11 @@ Version 1.5.2 - SVN [also CVE-2009-1578] - Fixed unsanitized shell command in example IMAP username mapping function (map_yp_alias) (Thanks to Niels Teusink). [CVE-2009-1579] + - Fixed session fixation issues where someone who can modify a user's + cookies could gain control of their login session. The SquirrelMail + base URI is now uniformly generated, extraneous cookies are cleaned + up and session IDs are regenerated upon every login (Thanks to Tomas + Hoger). [CVE-2009-1580] Version 1.5.1 (branched on 2006-02-12) --------------------------------------