Release date:
Updated on:
Affected Systems:
Mozilla Bugzilla 4.2rc1
Mozilla Bugzilla 4.1.3
Mozilla Bugzilla 4.1.3
Mozilla Bugzilla 4.0.4
Mozilla Bugzilla 4.0.3
Mozilla Bugzilla 4.0.2
Mozilla Bugzilla 3.x
Mozilla Bugzilla 3.6.8
Mozilla Bugzilla 3.6.7
Mozilla Bugzilla 3.6.6
Mozilla Bugzilla 3.4.14
Mozilla Bugzilla 3.4.13
Mozilla Bugzilla 3.4.12
Mozilla Bugzilla 4.2rc2
Mozilla Bugzilla 4.2rc1
Mozilla Bugzilla 4.1.1
Mozilla Bugzilla 4.0.4
Mozilla Bugzilla 4.0.3
Mozilla Bugzilla 4.0.2
Unaffected system:
Mozilla bug Zilla 4.2
Mozilla Bugzilla 4.0.5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52135
Cve id: CVE-2012-0453
Bugzilla is an open-source defect tracking system that manages the entire lifecycle of defects in software development, such as submitting, repairing, and disabling defects.
Bugzilla has a security vulnerability in HTTP request verification, which can be exploited to modify some Bug data or execute some management tasks.
<* Source: Mario Gomes
Link: http://secunia.com/advisories/48133/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Mozilla
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.mozilla.org/security/