Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4689 to the following vulnerability: Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions. Affected Mantis versions: before 1.1.3 References: http://www.openwall.com/lists/oss-security/2008/10/20/1 http://www.mantisbt.org/bugs/changelog_page.php http://www.mantisbt.org/bugs/view.php?id=9664 Proposed patch: http://www.mantisbt.org/bugs/file_download.php?file_id=1988&type=bug
This issue was addressed in: Fedora: https://admin.fedoraproject.org/updates/F8/FEDORA-2008-9015 https://admin.fedoraproject.org/updates/F9/FEDORA-2008-8925