CVE-2009-0486
published 2009-02-09CVE-2009-0486: Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and…
PriorityP430high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
0.57%
43.8th percentile
Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r4gm-vpf3-q479: Bugzilla 3
ghsa_unreviewed·2022-05-02
CVE-2009-0486 [HIGH] CWE-352 GHSA-r4gm-vpf3-q479: Bugzilla 3
Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.
Red Hat
bugzilla: CSRF protection bypass when running under mod_perl
vendor_redhat·2009-02-09·CVSS 7.5
CVE-2009-0486 [HIGH] CWE-352 bugzilla: CSRF protection bypass when running under mod_perl
bugzilla: CSRF protection bypass when running under mod_perl
Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0486 bugzilla: CSRF protection bypass when running under mod_perl
bugzilla·2009-02-10·CVSS 7.5
CVE-2009-0486 [HIGH] CVE-2009-0486 bugzilla: CSRF protection bypass when running under mod_perl
CVE-2009-0486 bugzilla: CSRF protection bypass when running under mod_perl
Name: CVE-2009-0486
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0486
Assigned: 20090209
Reference: CONFIRM: http://www.bugzilla.org/security/3.0.7/
Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls
the srand function at startup time, which causes Apache children to
have the same seed and produce insufficiently random numbers for
random tokens, which allows remote attackers to bypass cross-site
request forgery (CSRF) protection mechanisms and conduct unauthorized
activities as other users.
Discussion:
bugzilla-3.2.2-2.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/bugzilla-3.2.2-2.fc9
---
bugzilla-3.2.2-2.fc10 has been submitted as an
Bugzilla
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F9]
bugzilla·2009-02-09·CVSS 7.1
CVE-2008-4437 [HIGH] CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F9]
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=484757,
---
Correct update submission URL is:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&bugs=484757,CVE-2008-6098,CVE-2009-0481,CVE-2009-0482,CVE-2009-0483,CVE-2009-0484,CVE-2009-0485,CVE-2009-0486
---
*** Bug 465958 has been marked as a duplicate of this bug. ***
---
CVE-2008-4437 fixed in upstream 3.0.5 is still unfixed too, adding it to this tracking bug, u
Bugzilla
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F10]
bugzilla·2009-02-09·CVSS 7.1
CVE-2008-4437 [HIGH] CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F10]
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F10]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%2010&bugs=484756,
---
Correct update submission URL is:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&bugs=484756,CVE-2008-6098,CVE-2009-0481,CVE-2009-0482,CVE-2009-0483,CVE-2009-0484,CVE-2009-0485,CVE-2009-0486
---
*** Bug 465959 has been marked as a duplicate of this bug. ***
---
CVE-2008-4437 fixed in upstream 3.0.5 is still unfixed too, adding it to this tracking bug
http://secunia.com/advisories/34361http://www.bugzilla.org/security/3.0.7/http://www.securityfocus.com/bid/33581https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.htmlhttp://secunia.com/advisories/34361http://www.bugzilla.org/security/3.0.7/http://www.securityfocus.com/bid/33581https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.html
2009-02-09
Published