HomeSecurityPatch released to address Bugzilla vulnerability

Patch released to address Bugzilla vulnerability

bugzilla vulnerabilities

A serious vulnerability has been discovered in the Bugzilla application, which is used to track bugs by large organizations and individuals around the world. The vulnerability is quite serious, as it allows a user to create a new account, using an email of their choice, without requiring validation. Such a security issue means that a user could see bugs in third-party software that is “tracked” by Bugzilla.

Check Point Software Technologies was the company that discovered the vulnerability and reported it to the Bugzilla technical team: “The bug allows unknown users to gain administrator privileges” and “by gaining administrator privileges, attackers can then view and edit private and confidential bug details,” the company says.

Due to the critical nature of the vulnerability, the Mozilla Foundation quickly released a patch and alerted prominent organizations about its availability. The new Bugzilla versions are available for download: 4.0.15, 4.2.11, 4.4.6, and 4.5.6. The
security advisory published states: “the ‘real name in the ‘login_name’ field was not properly filtered during account creation.”

The Bugzilla team was notified of the issue on September 29. On September 30, the technical department acknowledged the issue and proceeded to create a patch to resolve it. It should be noted that the Bugzilla software is used by, among others: Mozilla Firefox, Apache, OpenSSH, Eclipse, KDE, GNOME, the Wikimedia Foundation, Wireshark and Novell.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS