LWN.net Logo

Advertisement

E-Commerce & credit card processing - the Open Source way!

Advertise here

bugzilla: unauthorized account creation

Package(s):bugzilla CVE #(s):CVE-2007-5038
Created:September 25, 2007 Updated:September 26, 2007
Description: The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.
Alerts:
Fedora FEDORA-2007-2299 2007-09-25

(Log in to post comments)

bugzilla: unauthorized account creation

Posted Sep 27, 2007 17:49 UTC (Thu) by kreutzm (subscriber, #4700) [Link]

Neither Debian stable nor oldstable ships the vulnerable versions.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds