Summary: | <www-apps/bugzilla-{3.6.9,4.0.6,4.2.1}: Cross-Site Request Forgery Vulnerability (CVE-2012-{0465,0466}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | idl0r, web-apps |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://secunia.com/advisories/48835/ | ||
Whiteboard: | B4 [noglsa] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 428334, 458562 | ||
Bug Blocks: |
Description
Agostino Sarubbo
2012-04-21 09:36:48 UTC
CVE-2012-0466 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0466): template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1 does not properly handle multiple logins, which allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive bug information via a crafted web page. CVE-2012-0465 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0465): Bugzilla 3.5.x and 3.6.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1, when the inbound_proxies option is enabled, does not properly validate the X-Forwarded-For HTTP header, which allows remote attackers to bypass the lockout policy via a series of authentication requests with (1) different IP address strings in this header or (2) a long string in this header. 18 Apr 2012; Christian Ruppert <idl0r@gentoo.org> +bugzilla-3.6.9.ebuild, -bugzilla-4.0.5.ebuild, +bugzilla-4.0.6.ebuild, -bugzilla-4.2.ebuild, +bugzilla-4.2.1.ebuild: Version bumps re CVE-2012-0465 and CVE-2012-0466 Thanks, Christian. May we proceed with stabilization of 3.6.9? Go ahead. (In reply to comment #3) > Go ahead. This bug is 11 months old and there have been 11 vulnerabilities found since then. See bugs 428334, 433776, 443162, and 458562. We now need at least versions 3.6.13, 4.0.10, and 4.2.5 in the tree. |