OSVDB ID: 69221

Title: Bugzilla Server Push Crafted URL Response Splitting CRLF Injection

Info

Disclosure

Nov 02, 2010

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Nov 02, 2010

Description

Bugzilla contains a flaw when Server Push is enabled. The issue is triggered when a remote attacker injects arbitrary HTTP headers and content with a crafted URL. This may allow an attacker to conduct HTTP response splitting attacks. This may lead to XSS or other vulnerabilities.

Classification

Location: Remote / Network Access, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Upgrade
Exploit: Exploit Unknown
Disclosure: Vendor Verified
OSVDB: Web Related

Solution

Upgrade to version 3.2.9, 3.4.9, 3.6.3, 4.0rc1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Bugzilla

Bugzilla

3.2.8
3.4.8
3.6.2
3.7.3

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/69221