LWN.net Logo

bugzilla: multiple vulnerabilities

Package(s):bugzilla CVE #(s):CVE-2012-0440 CVE-2012-0448
Created:February 13, 2012 Updated:February 15, 2012
Description: From the CVE entries:

Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 allows remote attackers to hijack the authentication of arbitrary users for requests that use the JSON-RPC API. (CVE-2012-0440)

Bugzilla 2.x and 3.x before 3.4.14, 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 does not reject non-ASCII characters in e-mail addresses of new user accounts, which makes it easier for remote authenticated users to spoof other user accounts by choosing a similar e-mail address. (CVE-2012-0448)

Alerts:
Fedora FEDORA-2012-1218 2012-02-10
Fedora FEDORA-2012-1189 2012-02-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds