Oval Definition:oval:org.opensuse.security:def:20154499
Revision Date:2022-06-30Version:1
Title:CVE-2015-4499
Description:

Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows remote attackers to obtain the default privileges for an arbitrary domain name by placing that name in a substring of an address, as demonstrated by truncation of an @mozilla.com.example.com address to an @mozilla.com address.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2015-4499
SUSE CVE-2015-4499
Platform(s):openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • bugzilla-5.0.6-4.2 is installed
  • OR bugzilla-apache-5.0.6-4.2 is installed
  • OR bugzilla-lang-de-5.0.6-4.2 is installed
  • BACK