CVE-2010-4568
Published: 28 January 2011
Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not properly generate random values for cookies and tokens, which allows remote attackers to obtain access to arbitrary accounts via unspecified vectors, related to an insufficient number of calls to the srand function.
Priority
Status
Package | Release | Status |
---|---|---|
bugzilla Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Ignored
(end of life)
|
|
karmic |
Ignored
(end of life)
|
|
lucid |
Ignored
(end of life)
|
|
maverick |
Ignored
(end of life)
|
|
natty |
Not vulnerable
|
|
oneiric |
Ignored
(end of life)
|
|
precise |
Does not exist
(dropped by debian)
|
|
quantal |
Does not exist
(dropped by debian)
|
|
raring |
Does not exist
(dropped by debian)
|
|
saucy |
Does not exist
(dropped by debian)
|
|
upstream |
Released
(3.2.10, 3.4.10, 3.6.4)
|
|
Patches: upstream: https://bugzilla.mozilla.org/attachment.cgi?id=506031&action=diff vendor: http://www.debian.org/security/2011/dsa-2322 |