Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 193062
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 193062 depends on: Show dependency tree
Bug 193062 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-09-19 13:51 0000
From Bugzilla:

* Even with account creation disabled, users can use the WebService to
  create an account.

We strongly advise that 2.23.x and 3.0.x users upgrade to 3.0.2
immediately. Users of CVS HEAD or 3.1.1 should upgrade to 3.1.2
immediately. This is critical if you have a "requirelogin" installation
and also have the WebService enabled.


Vulnerability Details
=====================

Class:       Unauthorized Access
Versions:    2.23.3 and above.
Description: Bugzilla::WebService::User::offer_account_by_email does
             not check the "createemailregexp" parameter, and thus
             allows users to create accounts who would normally be
             denied account creation.
             The "emailregexp" parameter is still checked.
             If you do not have the SOAP::Lite Perl module installed on
             your Bugzilla system, your system is not vulnerable
             (because the Bugzilla WebService will not be enabled).

Reference:   https://bugzilla.mozilla.org/show_bug.cgi?id=395632


In our tree, this only affects 3.0.1. Please bump to 3.0.2.

------- Comment #1 From Robert Buchholz 2007-09-19 13:52:41 0000 -------
Whiteboard. Maintainers already cc'ed.

------- Comment #2 From Gunnar Wrobel 2007-09-19 14:56:03 0000 -------
Bumped to 3.0.2, removed insecure 3.0.1. Marked unstable on all arches, nothing
to stabilize. webapps done here

------- Comment #3 From Robert Buchholz 2007-09-19 15:38:56 0000 -------
Thanks. [noglsa] here.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug