|
Bugzilla Pseudo-Random Number Generator Shared Seed Vulnerability
Bugzilla is prone to a vulnerability caused by the use of a shared random seed. This issue occurs when Bugzilla is running under mod_perl. An attacker may exploit this issue to predict random values generated by Bugzilla. This may reveal sensitive information such as attachment files or may allow the attacker to bypass cross-site request-forgery protection by predicting random token values. Other attacks may also be possible. This issue affects Bugzilla 3.0.7, 3.2.1, and 3.3.2 when run under mod_perl. |
|
|
Privacy Statement |