Lucene search

K
freebsdFreeBSDF8D3689E-6770-11DC-8BE8-02E0185F8D72
HistorySep 18, 2007 - 12:00 a.m.

bugzilla -- "createmailregexp" security bypass vulnerability

2007-09-1800:00:00
vuxml.freebsd.org
25

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.06

Percentile

93.6%

The Bugzilla development team reports:

Bugzilla::WebService::User::offer_account_by_email does
not check the “createemailregexp” parameter, and thus
allows users to create accounts who would normally be
denied account creation. The “emailregexp” parameter is
still checked. If you do not have the SOAP::Lite Perl
module installed on your Bugzilla system, your system is
not vulnerable (because the Bugzilla WebService will not
be enabled).

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchbugzilla= 3.*UNKNOWN
FreeBSDanynoarchbugzilla< 3.0.2UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.06

Percentile

93.6%

Related for F8D3689E-6770-11DC-8BE8-02E0185F8D72