CVE-2007-4538: Medium severity Bugzilla vulnerability
Published Aug 27, 2007
·Updated
emailin.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From address) option to the Email::Send::Sendmail function, probably involving shell metacharacters.
Affected Software
6 affected components
Bugzilla=3.0.0
Bugzilla=2.23.4
Bugzilla=2.6
Bugzilla=2.4
Bugzilla=2.8
Bugzilla=2.9
Remediation
Patch Available
Patch Available
Event History
Aug 27, 2007
CVE Published
09:17 PM
Aug 28, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4538?
CVE-2007-4538 has a high severity level due to its potential for remote code execution.
2
How do I fix CVE-2007-4538?
To fix CVE-2007-4538, upgrade Bugzilla to version 3.0.1 or later, which addresses this vulnerability.
3
What versions of Bugzilla are affected by CVE-2007-4538?
Bugzilla versions 2.23.4 through 3.0.0 are affected by CVE-2007-4538.
4
Can CVE-2007-4538 be exploited remotely?
Yes, CVE-2007-4538 can be exploited remotely by attackers through crafted email requests.
5
What types of attacks can CVE-2007-4538 enable?
CVE-2007-4538 can enable attackers to execute arbitrary shell commands on the affected system.