Release date:
Updated on:
Affected Systems:
Mozilla Bugzilla 4.x
Unaffected system:
Mozilla Bugzilla 4.0.4
Mozilla Bugzilla 3.6.8
Mozilla Bugzilla 3.4.14
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51783
Cve id: CVE-2012-0440
Bugzilla is an open-source defect tracking system that manages the entire lifecycle of defects in software development, such as submitting, repairing, and disabling defects.
Bugzilla has a CSRF security vulnerability in the implementation of jsonrpc. cgi. Successful exploitation of these vulnerabilities allows attackers to hijack authentication requests from arbitrary users using JSON-RPC APIs.
<* Source: Mario Gomes
Link: https://bugzilla.mozilla.org/show_bug.cgi? Id = 718319
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Mozilla
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.mozilla.org/security/