Title: Bugzilla Server Push Crafted URL Response Splitting CRLF Injection
Info
Disclosure
Nov 02, 2010
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Nov 02, 2010
Description
Bugzilla contains a flaw when Server Push is enabled. The issue is triggered when a remote attacker injects arbitrary HTTP headers and content with a crafted URL. This may allow an attacker to conduct HTTP response splitting attacks. This may lead to XSS or other vulnerabilities.
Classification
Location:
Remote / Network Access,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade to version 3.2.9, 3.4.9, 3.6.3, 4.0rc1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.