CVE-2014-1572: Medium severity red hat fedora vulnerability
The confirmcreateaccount function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=loginname as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1572?
CVE-2014-1572 has a medium severity rating that indicates potential impact on affected systems.
How do I fix CVE-2014-1572?
To fix CVE-2014-1572, upgrade Bugzilla to versions 4.0.15, 4.2.11, 4.4.6, or 4.5.6 or later.
Which versions of Bugzilla are affected by CVE-2014-1572?
CVE-2014-1572 affects Bugzilla versions from 2.x through 4.0.x before 4.0.15 and also affects 4.1.x, 4.2.x, 4.3.x, 4.4.x, and 4.5.x before their respective fixed versions.
Can CVE-2014-1572 be exploited remotely?
Yes, CVE-2014-1572 can be exploited remotely, allowing an attacker to potentially manipulate user account information.
What applications are vulnerable due to CVE-2014-1572?
CVE-2014-1572 specifically impacts Bugzilla applications running on versions affected as stated in the CVE report.