CVE-2010-4572: Code Injection
CRLF injection vulnerability in chart.cgi in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the query string, a different vulnerability than CVE-2010-2761 and CVE-2010-4411.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4572?
CVE-2010-4572 has a moderate severity rating as it allows attackers to inject arbitrary HTTP headers.
How do I fix CVE-2010-4572?
To fix CVE-2010-4572, update Bugzilla to the latest version that includes security patches addressing this vulnerability.
What versions of Bugzilla are affected by CVE-2010-4572?
CVE-2010-4572 affects Bugzilla versions before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2.
What types of attacks can be conducted using CVE-2010-4572?
Attackers can use CVE-2010-4572 to conduct HTTP response splitting attacks through CRLF injection.
Is CVE-2010-4572 related to any other vulnerabilities?
CVE-2010-4572 is a different vulnerability than CVE-2010-276 despite both relating to security issues in Bugzilla.