The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=login_name as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted.
Monthly Archives: October 2014
CVE-2014-3091
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.1.x and 7.2.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVE-2014-1573
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for certain CGI parameters, which allows remote attackers to conduct cross-site scripting (XSS) attacks by sending three values for a single parameter name.
Vuln: GNU Bash CVE-2014-7186 Local Memory Corruption Vulnerability
GNU Bash CVE-2014-7186 Local Memory Corruption Vulnerability
Vuln: GNU Bash CVE-2014-7169 Incomplete Fix Remote Code Execution Vulnerability
GNU Bash CVE-2014-7169 Incomplete Fix Remote Code Execution Vulnerability
Vuln: GNU Bash CVE-2014-6271 Remote Code Execution Vulnerability
GNU Bash CVE-2014-6271 Remote Code Execution Vulnerability
Vuln: IBM QRadar Security Information and Event Manager Multiple Security Vulnerabilities
IBM QRadar Security Information and Event Manager Multiple Security Vulnerabilities
GLSA 201410-02 (Normal): Locale-Maketext (and 1
Perl, Perl Locale-Maketext module: Multiple vulnerabilities
Fedora 21 Security Update: devscripts-2.14.8-1.fc21
Resolved Bugs
1059947 – CVE-2014-1833 devscripts: directory traversal flaw in uupdate
1059948 – devscripts: directory traversal flaw in uupdate [fedora-20]<br
Update to version 2.14.8, see http://metadata.ftp-master.debian.org/changelogs//main/d/devscripts/devscripts_2.14.8_changelog for details. Fixes CVE-2014-1833.
Fedora 19 Security Update: perl-Mojolicious-5.49-1.fc19
This version of Mojolicious fixes an assumption in CGI’s parameter handling that can result in parameter injection attacks.