CVE-2014-1572

Publication date 13 October 2014

Last updated 24 July 2024


Ubuntu priority

The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=login_name as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted.

Status

Package Ubuntu Release Status
bugzilla 14.04 LTS trusty Not in release
12.04 LTS precise Not in release
10.04 LTS lucid Ignored end of life