CVE-2015-4499: Input Validation
Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows remote attackers to obtain the default privileges for an arbitrary domain name by placing that name in a substring of an address, as demonstrated by truncation of an @mozilla.com.example.com address to an @mozilla.com address.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4499?
CVE-2015-4499 is considered a moderate severity vulnerability due to improper handling of long e-mail addresses, allowing privilege escalation for remote attackers.
How do I fix CVE-2015-4499?
To fix CVE-2015-4499, update your Bugzilla software to version 4.2.15, 4.4.10, or 5.0.1 or later.
Which versions of Bugzilla are affected by CVE-2015-4499?
CVE-2015-4499 affects Bugzilla versions 2.x, 3.x, and 4.x before 4.2.15, as well as 4.3.x and 4.4.x before 4.4.10 and 5.x before 5.0.1.
What type of vulnerability is CVE-2015-4499?
CVE-2015-4499 is a privilege escalation vulnerability related to e-mail address processing during account registration.
Who is impacted by CVE-2015-4499?
Users of affected Bugzilla versions are at risk of unauthorized privilege escalation due to CVE-2015-4499.