LWN.net Logo

bugzilla: LDAP data injection

Package(s):bugzilla CVE #(s):CVE-2012-3981
Created:September 5, 2012 Updated:September 11, 2012
Description: From the CVE entry:

Auth/Verify/LDAP.pm in Bugzilla 2.x and 3.x before 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 does not restrict the characters in a username, which might allow remote attackers to inject data into an LDAP directory via a crafted login attempt.

Alerts:
Mageia MGASA-2012-0255 2012-09-04
Fedora FEDORA-2012-13163 2012-09-10
Fedora FEDORA-2012-13171 2012-09-10
Mandriva MDVSA-2013:066 2013-04-08
Mageia MGASA-2013-0117 2013-04-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds