|
|
| |
|
| |
bugzilla: LDAP data injection
| Package(s): | bugzilla |
CVE #(s): | CVE-2012-3981
|
| Created: | September 5, 2012 |
Updated: | September 11, 2012 |
| Description: |
From the CVE entry:
Auth/Verify/LDAP.pm in Bugzilla 2.x and 3.x before 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 does not restrict the characters in a username, which might allow remote attackers to inject data into an LDAP directory via a crafted login attempt. |
| Alerts: |
|
( Log in to post comments)
|
|
|