Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not properly generate random values for cookies and tokens, which allows remote attackers to obtain access to arbitrary accounts via unspecified vectors, related to an insufficient number of calls to the srand function.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
History
21 Nov 2024, 01:21
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053665.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053678.html - | |
References | () http://osvdb.org/70700 - | |
References | () http://secunia.com/advisories/43033 - Vendor Advisory | |
References | () http://secunia.com/advisories/43165 - | |
References | () http://www.bugzilla.org/security/3.2.9/ - Vendor Advisory | |
References | () http://www.debian.org/security/2011/dsa-2322 - | |
References | () http://www.securityfocus.com/bid/45982 - | |
References | () http://www.vupen.com/english/advisories/2011/0207 - Vendor Advisory | |
References | () http://www.vupen.com/english/advisories/2011/0271 - | |
References | () https://bugzilla.mozilla.org/attachment.cgi?id=506031&action=diff - | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=619594 - | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=621591 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/65001 - |
Information
Published : 2011-01-28 16:00
Updated : 2024-11-21 01:21
NVD link : CVE-2010-4568
Mitre link : CVE-2010-4568
CVE.ORG link : CVE-2010-4568
JSON object : View
Products Affected
mozilla
- bugzilla
CWE
CWE-264
Permissions, Privileges, and Access Controls