Bugzilla Control Characters Spoofing Vulnerability
BID:66970
Info
Bugzilla Control Characters Spoofing Vulnerability
| Bugtraq ID: | 66970 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2014 12:00AM |
| Updated: | Apr 17 2014 12:00AM |
| Credit: | Manish Goregaokar |
| Vulnerable: |
Mozilla Bugzilla 4.2.5 Mozilla Bugzilla 4.2.4 Mozilla Bugzilla 4.0.10 Mozilla Bugzilla 4.0.9 Mozilla Bugzilla 4.0.5 Mozilla Bugzilla 4.0.4 Mozilla Bugzilla 4.0.3 Mozilla Bugzilla 4.0.2 Mozilla Bugzilla 4.5.2 Mozilla Bugzilla 4.4.2 Mozilla Bugzilla 4.4.1 Mozilla Bugzilla 4.4 Mozilla Bugzilla 4.2.7 Mozilla Bugzilla 4.2.6 Mozilla Bugzilla 4.2.3 Mozilla Bugzilla 4.2.2 Mozilla Bugzilla 4.2.1 Mozilla Bugzilla 4.2 Mozilla Bugzilla 4.0.8 Mozilla Bugzilla 4.0.7 Mozilla Bugzilla 4.0.6 Mozilla Bugzilla 4.0.11 Mozilla Bugzilla 4.0.1 |
| Not Vulnerable: |
Mozilla Bugzilla 4.5.3 Mozilla Bugzilla 4.4.3 Mozilla Bugzilla 4.2.8 Mozilla Bugzilla 4.0.12 |
Discussion
Bugzilla Control Characters Spoofing Vulnerability
Bugzilla is prone to a security vulnerability that may allow attackers to conduct spoofing attacks.
An attacker can exploit this issue to conduct spoofing attacks. This may aid in further attacks.
Versions prior to Bugzilla 4.0.12, 4.2.8, 4.4.3, and 4.5.3 are vulnerable.
Bugzilla is prone to a security vulnerability that may allow attackers to conduct spoofing attacks.
An attacker can exploit this issue to conduct spoofing attacks. This may aid in further attacks.
Versions prior to Bugzilla 4.0.12, 4.2.8, 4.4.3, and 4.5.3 are vulnerable.
Exploit / POC
Bugzilla Control Characters Spoofing Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
Bugzilla Control Characters Spoofing Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.