Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 114237 - Bugzilla mail might be exploitable to do funny stuff
Summary: Bugzilla mail might be exploitable to do funny stuff
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Auditing (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-12-02 01:19 UTC by Thierry Carrez (RETIRED)
Modified: 2007-06-29 08:28 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thierry Carrez (RETIRED) gentoo-dev 2005-12-02 01:19:03 UTC
Something to investigate, to see if it can have security implications :

By entering a bug with a CR in the summary field you end up with funny bugzilla
mail. Let's take this one for example :

===============================
...
From: bugzilla-daemon@gentoo.org
To: security@gentoo.org
Subject: [Bug 114205] www-apps/trac
Message-Id: <E1Ei6rP-0002c1-Mi@nuthatch.gentoo.org>
Date: Fri, 02 Dec 2005 09:05:43 +0000
X-Spam-Checker-Version: SpamAssassin 3.0.4-gr0 (2005-06-05) on 
	toucan.gentoo.org
X-Spam-Level: 
X-Spam-Status: No, score=-1.2 required=5.0 tests=AWL,FORGED_RCVD_HELO,
	NO_REAL_NAME autolearn=no version=3.0.4-gr0

SQL injection
In-Reply-To: <bug-114205@bugs.gentoo.org>
X-Bugzilla-Reason: AssignedTo

Clear-Text: http://bugs.gentoo.org/show_bug.cgi?id=114205
Secure: https://bugs.gentoo.org/show_bug.cgi?id=114205
...
=======================

It's clearly a bug, but was wondering if you can exploit it to overload headers...
Comment 1 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2007-01-10 21:10:17 UTC
*waves at security folks*
Hi guys, you should be able to close this one, Summary should have all non-space whitespace converted into single spaces now.

P.S. Don't mind me, I was working on bugzilla bugs since I'm doing some of the admin work now, and the admin perms included this bug in my search, which I would not normally have seen.
Comment 2 Matt Drew (RETIRED) gentoo-dev 2007-04-04 21:14:57 UTC
Thanks Robin, we're outta here.