FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-0465

This CVE name corresponds to:

Entered Topic
2012-04-21 bugzilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-0465
Phase Assigned(20120109)

Description

Bugzilla 3.5.x and 3.6.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1, when the inbound_proxies option is enabled, does not properly validate the X-Forwarded-For HTTP header, which allows remote attackers to bypass the lockout policy via a series of authentication requests with (1) different IP address strings in this header or (2) a long string in this header.

References

Source Reference
BUGTRAQ 20120418 Security advisory for Bugzilla 4.2.1, 4.0.6 and 3.6.9
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=728639
FEDORA FEDORA-2012-6282
FEDORA FEDORA-2012-6368
FEDORA FEDORA-2012-6396