CVE-2010-4567
published 2011-01-28CVE-2010-4567: Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 does not properly handle whitespace preceding a (1) javascript: or (2)…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.79%
76.0th percentile
Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 does not properly handle whitespace preceding a (1) javascript: or (2) data: URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the URL (aka bug_file_loc) field.
Affected
98 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | <= 3.2.9 | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rvrf-fv66-542r: Bugzilla before 3
ghsa_unreviewed·2022-05-17
CVE-2010-4567 [MEDIUM] CWE-79 GHSA-rvrf-fv66-542r: Bugzilla before 3
Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 does not properly handle whitespace preceding a (1) javascript: or (2) data: URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the URL (aka bug_file_loc) field.
Red Hat
kernel: ipv6: skb_dst() can be NULL in ipv6_hop_jumbo()
vendor_redhat·2009-01-14·CVSS 7.8
CVE-2010-0006 [HIGH] CWE-476 kernel: ipv6: skb_dst() can be NULL in ipv6_hop_jumbo()
kernel: ipv6: skb_dst() can be NULL in ipv6_hop_jumbo()
The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers to cause a denial of service (NULL pointer dereference) via an invalid IPv6 jumbogram, a related issue to CVE-2007-4567.
Statement: Not vulnerable. This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5 and Red Hat Enterprise MRG as they did not have support for network namespaces, and did not include upstream commit 483a47d2 that introduced the problem.
Red Hat
kernel: ipv6_hop_jumbo remote system crash
vendor_redhat·2007-09-07·CVSS 7.8
CVE-2007-4567 [HIGH] CWE-228 kernel: ipv6_hop_jumbo remote system crash
kernel: ipv6_hop_jumbo remote system crash
The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted IPv6 packet.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 3, 4 and Red Hat Enterprise MRG. Shipped kernels do not include upstream commit a11d206d that introduced the problem.
This upstream commit was backported in Red Hat Enterprise Linux 5 via RHBA-2008:0314. It was reported and addressed in Red Hat Enterprise Linux 5 via RHSA-2010:0019.
No detection rules found.
No public exploits indexed.
Bugzilla
bugzilla: multiple security issues
bugzilla·2011-01-26
[HIGH] bugzilla: multiple security issues
bugzilla: multiple security issues
Bugzilla upstream has released updates fixing multiple security issues:
http://www.bugzilla.org/security/3.2.9/
Quoting upstream advisory:
Summary
Bugzilla is a Web-based bug-tracking system used by a large number of
software projects.
Recently, Mozilla expanded its security bug bounty program to include web
applications (http://www.mozilla.org/security/bug-bounty.html). As a result,
several new security issues affecting Bugzilla were discovered:
* A weakness in Bugzilla could allow a user to gain unauthorized access
to another Bugzilla account.
* A weakness in the Perl CGI.pm module allows injecting HTTP headers
and content to users via several pages in Bugzilla.
* The new user autocomplete functionality in Bugzilla 4.0 is vulnerable
to a cross-
Bugzilla
CVE-2007-4567 kernel: ipv6_hop_jumbo remote system crash
bugzilla·2009-12-18·CVSS 7.8
CVE-2007-4567 [HIGH] CVE-2007-4567 kernel: ipv6_hop_jumbo remote system crash
CVE-2007-4567 kernel: ipv6_hop_jumbo remote system crash
Originally discovered by Victor Julien that there is a way to crash the Linux kernel by sending a single IPv6 packet at it.
1) The CVE-2007-4567 issue was reported to Red Hat in September 2007. Red Hat Enterprise Linux 5 was found not to be affected.
2) On December 18, 2009, a customer reported to us that Red Hat Enterprise Linux 5 was vulnerable to CVE-2007-4567.
3) Investigations showed that the issue was introduced in the RHBA-2008-0314 update on May 21, 2008 via a backport of a collection of patches for DoD IPv6 conformance.
4) Updates released on January 7, 2010 for Red Hat Enterprise Linux 5, resolving CVE-2007-4567.
Note that the Linux kernels as shipped with Red Hat Enterprise Linux 3, 4, and Red Hat Enterprise MRG are
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053665.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-February/053678.htmlhttp://osvdb.org/70699http://secunia.com/advisories/43033http://secunia.com/advisories/43165http://www.bugzilla.org/security/3.2.9/http://www.debian.org/security/2011/dsa-2322http://www.securityfocus.com/bid/45982http://www.vupen.com/english/advisories/2011/0207http://www.vupen.com/english/advisories/2011/0271https://bugzilla.mozilla.org/show_bug.cgi?id=619588https://exchange.xforce.ibmcloud.com/vulnerabilities/65004http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053665.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-February/053678.htmlhttp://osvdb.org/70699http://secunia.com/advisories/43033http://secunia.com/advisories/43165http://www.bugzilla.org/security/3.2.9/http://www.debian.org/security/2011/dsa-2322http://www.securityfocus.com/bid/45982http://www.vupen.com/english/advisories/2011/0207http://www.vupen.com/english/advisories/2011/0271https://bugzilla.mozilla.org/show_bug.cgi?id=619588https://exchange.xforce.ibmcloud.com/vulnerabilities/65004
2011-01-28
Published