Bugzilla Util. pm Privilege Escalation Vulnerability (CVE-2015-4499)
Bugzilla Util. pm Privilege Escalation Vulnerability (CVE-2015-4499)
Release date:
Updated on:
Affected Systems:
Bugzilla 5.x
Bugzilla 4.x
Bugzilla 3.x
Bugzilla 2.x
Description:
CVE (CAN) ID: CVE-2015-4499
Bugzilla is an open source defect tracking system.
Bugzilla 2.x, 3.x, 4.x, 5. in Version x, Util. when pm processes email addresses with more than 127 characters in account registration, it will be truncated by default, which allows remote attackers to obtain accounts created from different email addresses.
<* Source: Frederic Buclin
Byron Jones
Netanel Rubin
*>
Suggestion:
Vendor patch:
Bugzilla
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.bugzilla.org/download/
This article permanently updates the link address: