[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-4499Date: (C)2015-09-15   (M)2023-12-22


Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows remote attackers to obtain the default privileges for an arbitrary domain name by placing that name in a substring of an address, as demonstrated by truncation of an @mozilla.com.example.com address to an @mozilla.com address.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1033542
http://seclists.org/bugtraq/2015/Sep/48
http://seclists.org/bugtraq/2015/Sep/49
FEDORA-2015-15767
FEDORA-2015-15768
FEDORA-2015-15769
http://packetstormsecurity.com/files/133578/Bugzilla-Unauthorized-Account-Creation.html
https://bug1202447.bmoattachments.org/attachment.cgi?id=8657861
https://bugzilla.mozilla.org/show_bug.cgi?id=1202447

CPE    205
cpe:/a:mozilla:bugzilla:2.22:rc1
cpe:/a:mozilla:bugzilla:2.14.2
cpe:/a:mozilla:bugzilla:2.14.1
cpe:/a:mozilla:bugzilla:4.0:rc1
...
CWE    1
CWE-20
OVAL    2
oval:org.secpod.oval:def:109617
oval:org.secpod.oval:def:109632

© SecPod Technologies