Get a Pentest and security assessment of your IT network.

Advisories

Bugzilla XSRF Randomization Vulnerability

Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, generated insufficiently random numbers, resulting in all random tokens being the same, all CSRF protection being defeated, and the new attachment_base functionality being compromised.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/74582/bugzilla-xsrf.txt

Source: https://packetstormsecurity.com/files/74582/Bugzilla-XSRF-Randomization-Vulnerability.html

Related posts
Advisories

crossZone.txt

Advisories

Secunia Security Advisory 16900

Advisories

Secunia Security Advisory 19793

Advisories

Secunia Security Advisory 22534