CVE Vulnerabilities

CVE-2012-0465

Published: Apr 27, 2012 | Modified: Aug 14, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Bugzilla 3.5.x and 3.6.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1, when the inbound_proxies option is enabled, does not properly validate the X-Forwarded-For HTTP header, which allows remote attackers to bypass the lockout policy via a series of authentication requests with (1) different IP address strings in this header or (2) a long string in this header.

Affected Software

Name Vendor Start Version End Version
Bugzilla Mozilla 3.5.1 (including) 3.5.1 (including)
Bugzilla Mozilla 3.5.2 (including) 3.5.2 (including)
Bugzilla Mozilla 3.5.3 (including) 3.5.3 (including)
Bugzilla Mozilla 3.6.0 (including) 3.6.0 (including)
Bugzilla Mozilla 3.6.1 (including) 3.6.1 (including)
Bugzilla Mozilla 3.6.2 (including) 3.6.2 (including)
Bugzilla Mozilla 3.6.3 (including) 3.6.3 (including)
Bugzilla Mozilla 3.6.4 (including) 3.6.4 (including)
Bugzilla Mozilla 3.6.5 (including) 3.6.5 (including)
Bugzilla Mozilla 3.6.6 (including) 3.6.6 (including)
Bugzilla Mozilla 3.6.7 (including) 3.6.7 (including)
Bugzilla Mozilla 3.6.8 (including) 3.6.8 (including)
Bugzilla Mozilla 3.7.1 (including) 3.7.1 (including)
Bugzilla Mozilla 3.7.2 (including) 3.7.2 (including)
Bugzilla Mozilla 3.7.3 (including) 3.7.3 (including)
Bugzilla Mozilla 4.0.1 (including) 4.0.1 (including)
Bugzilla Mozilla 4.0.2 (including) 4.0.2 (including)
Bugzilla Mozilla 4.0.3 (including) 4.0.3 (including)
Bugzilla Mozilla 4.0.4 (including) 4.0.4 (including)
Bugzilla Mozilla 4.0.5 (including) 4.0.5 (including)
Bugzilla Mozilla 4.1.1 (including) 4.1.1 (including)
Bugzilla Mozilla 4.1.2 (including) 4.1.2 (including)
Bugzilla Mozilla 4.1.3 (including) 4.1.3 (including)
Bugzilla Mozilla 4.2 (including) 4.2 (including)
Bugzilla Mozilla 4.2-rc1 (including) 4.2-rc1 (including)
Bugzilla Mozilla 4.2-rc2 (including) 4.2-rc2 (including)
Bugzilla Ubuntu hardy *
Bugzilla Ubuntu lucid *
Bugzilla Ubuntu natty *
Bugzilla Ubuntu oneiric *
Bugzilla Ubuntu upstream *

References