CVE-2011-2381: Code Injection
CRLF injection vulnerability in Bugzilla 2.17.1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 allows remote attackers to inject arbitrary e-mail headers via an attachment description in a flagmail notification.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2381?
CVE-2011-2381 is classified as a moderate severity vulnerability, allowing for potential exploitation through CRLF injection.
What versions of Bugzilla are affected by CVE-2011-2381?
CVE-2011-2381 affects Bugzilla versions 2.17.1 through 2.22.7, and multiple versions up to and including 4.0.x before 4.0.2 and 4.1.x before 4.1.3.
How do I fix CVE-2011-2381?
To fix CVE-2011-2381, upgrade Bugzilla to version 4.1.3 or later.
What type of attack does CVE-2011-2381 facilitate?
CVE-2011-2381 allows remote attackers to inject arbitrary e-mail headers via an attachment description.
Is there a known exploit for CVE-2011-2381?
There are no public exploits specifically targeting CVE-2011-2381, but the vulnerability can be leveraged for email header injection attacks.