First published: Sun Jan 03 2016(Updated: )
Template.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2 does not properly construct CSV files, which allows remote attackers to obtain sensitive information by leveraging a web browser that interprets CSV data as JavaScript code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.0 | |
Mozilla Bugzilla | =2.2 | |
Mozilla Bugzilla | =2.4 | |
Mozilla Bugzilla | =2.6 | |
Mozilla Bugzilla | =2.8 | |
Mozilla Bugzilla | =2.10 | |
Mozilla Bugzilla | =2.12 | |
Mozilla Bugzilla | =2.14 | |
Mozilla Bugzilla | =2.14.1 | |
Mozilla Bugzilla | =2.14.2 | |
Mozilla Bugzilla | =2.14.3 | |
Mozilla Bugzilla | =2.14.4 | |
Mozilla Bugzilla | =2.14.5 | |
Mozilla Bugzilla | =2.16 | |
Mozilla Bugzilla | =2.16.1 | |
Mozilla Bugzilla | =2.16.2 | |
Mozilla Bugzilla | =2.16.3 | |
Mozilla Bugzilla | =2.16.4 | |
Mozilla Bugzilla | =2.16.5 | |
Mozilla Bugzilla | =2.16.6 | |
Mozilla Bugzilla | =2.16.7 | |
Mozilla Bugzilla | =2.16.8 | |
Mozilla Bugzilla | =2.16.9 | |
Mozilla Bugzilla | =2.16.10 | |
Mozilla Bugzilla | =2.16.11 | |
Mozilla Bugzilla | =2.18 | |
Mozilla Bugzilla | =2.18.1 | |
Mozilla Bugzilla | =2.18.2 | |
Mozilla Bugzilla | =2.18.3 | |
Mozilla Bugzilla | =2.18.4 | |
Mozilla Bugzilla | =2.18.5 | |
Mozilla Bugzilla | =2.18.6 | |
Mozilla Bugzilla | =2.20 | |
Mozilla Bugzilla | =2.20.1 | |
Mozilla Bugzilla | =2.20.2 | |
Mozilla Bugzilla | =2.20.3 | |
Mozilla Bugzilla | =2.20.4 | |
Mozilla Bugzilla | =2.20.5 | |
Mozilla Bugzilla | =2.20.6 | |
Mozilla Bugzilla | =2.20.7 | |
Mozilla Bugzilla | =2.22 | |
Mozilla Bugzilla | =2.22.1 | |
Mozilla Bugzilla | =2.22.2 | |
Mozilla Bugzilla | =2.22.3 | |
Mozilla Bugzilla | =2.22.4 | |
Mozilla Bugzilla | =2.22.5 | |
Mozilla Bugzilla | =2.22.6 | |
Mozilla Bugzilla | =2.22.7 | |
Mozilla Bugzilla | =3.0 | |
Mozilla Bugzilla | =3.0.1 | |
Mozilla Bugzilla | =3.0.2 | |
Mozilla Bugzilla | =3.0.3 | |
Mozilla Bugzilla | =3.0.4 | |
Mozilla Bugzilla | =3.0.5 | |
Mozilla Bugzilla | =3.0.6 | |
Mozilla Bugzilla | =3.0.7 | |
Mozilla Bugzilla | =3.0.8 | |
Mozilla Bugzilla | =3.0.9 | |
Mozilla Bugzilla | =3.0.10 | |
Mozilla Bugzilla | =3.0.11 | |
Mozilla Bugzilla | =3.2 | |
Mozilla Bugzilla | =3.2.1 | |
Mozilla Bugzilla | =3.2.2 | |
Mozilla Bugzilla | =3.2.3 | |
Mozilla Bugzilla | =3.2.4 | |
Mozilla Bugzilla | =3.2.5 | |
Mozilla Bugzilla | =3.2.6 | |
Mozilla Bugzilla | =3.2.7 | |
Mozilla Bugzilla | =3.2.8 | |
Mozilla Bugzilla | =3.2.9 | |
Mozilla Bugzilla | =3.2.10 | |
Mozilla Bugzilla | =3.4 | |
Mozilla Bugzilla | =3.4.1 | |
Mozilla Bugzilla | =3.4.2 | |
Mozilla Bugzilla | =3.4.3 | |
Mozilla Bugzilla | =3.4.5 | |
Mozilla Bugzilla | =3.4.6 | |
Mozilla Bugzilla | =3.4.7 | |
Mozilla Bugzilla | =3.4.8 | |
Mozilla Bugzilla | =3.4.9 | |
Mozilla Bugzilla | =3.4.10 | |
Mozilla Bugzilla | =3.4.11 | |
Mozilla Bugzilla | =3.4.12 | |
Mozilla Bugzilla | =3.4.13 | |
Mozilla Bugzilla | =3.4.14 | |
Mozilla Bugzilla | =3.6 | |
Mozilla Bugzilla | =3.6.1 | |
Mozilla Bugzilla | =3.6.2 | |
Mozilla Bugzilla | =3.6.3 | |
Mozilla Bugzilla | =3.6.4 | |
Mozilla Bugzilla | =3.6.5 | |
Mozilla Bugzilla | =3.6.6 | |
Mozilla Bugzilla | =3.6.7 | |
Mozilla Bugzilla | =3.6.8 | |
Mozilla Bugzilla | =3.6.9 | |
Mozilla Bugzilla | =3.6.10 | |
Mozilla Bugzilla | =3.6.11 | |
Mozilla Bugzilla | =3.6.12 | |
Mozilla Bugzilla | =3.6.13 | |
Mozilla Bugzilla | =4.0 | |
Mozilla Bugzilla | =4.0.1 | |
Mozilla Bugzilla | =4.0.2 | |
Mozilla Bugzilla | =4.0.3 | |
Mozilla Bugzilla | =4.0.4 | |
Mozilla Bugzilla | =4.0.5 | |
Mozilla Bugzilla | =4.0.6 | |
Mozilla Bugzilla | =4.0.7 | |
Mozilla Bugzilla | =4.0.8 | |
Mozilla Bugzilla | =4.0.9 | |
Mozilla Bugzilla | =4.0.10 | |
Mozilla Bugzilla | =4.0.11 | |
Mozilla Bugzilla | =4.0.12 | |
Mozilla Bugzilla | =4.0.13 | |
Mozilla Bugzilla | =4.0.14 | |
Mozilla Bugzilla | =4.0.15 | |
Mozilla Bugzilla | =4.0.16 | |
Mozilla Bugzilla | =4.0.17 | |
Mozilla Bugzilla | =4.0.18 | |
Mozilla Bugzilla | =4.2 | |
Mozilla Bugzilla | =4.2.1 | |
Mozilla Bugzilla | =4.2.2 | |
Mozilla Bugzilla | =4.2.3 | |
Mozilla Bugzilla | =4.2.4 | |
Mozilla Bugzilla | =4.2.5 | |
Mozilla Bugzilla | =4.2.6 | |
Mozilla Bugzilla | =4.2.7 | |
Mozilla Bugzilla | =4.2.8 | |
Mozilla Bugzilla | =4.2.9 | |
Mozilla Bugzilla | =4.2.10 | |
Mozilla Bugzilla | =4.2.11 | |
Mozilla Bugzilla | =4.2.12 | |
Mozilla Bugzilla | =4.2.13 | |
Mozilla Bugzilla | =4.2.14 | |
Mozilla Bugzilla | =4.2.15 | |
Mozilla Bugzilla | =4.4 | |
Mozilla Bugzilla | =4.4.1 | |
Mozilla Bugzilla | =4.4.2 | |
Mozilla Bugzilla | =4.4.3 | |
Mozilla Bugzilla | =4.4.4 | |
Mozilla Bugzilla | =4.4.5 | |
Mozilla Bugzilla | =4.4.6 | |
Mozilla Bugzilla | =4.4.7 | |
Mozilla Bugzilla | =4.4.8 | |
Mozilla Bugzilla | =4.4.9 | |
Mozilla Bugzilla | =4.4.10 | |
Mozilla Bugzilla | =5.0 | |
Mozilla Bugzilla | =5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8509 is classified as a moderate severity vulnerability due to the potential for information leakage.
You can fix CVE-2015-8509 by upgrading to Bugzilla version 4.2.16, 4.4.11, or 5.0.2 or later.
CVE-2015-8509 affects Bugzilla versions 2.x, 3.x, and certain 4.x and 5.x versions prior to their respective fixes.
CVE-2015-8509 is a vulnerability that allows remote attackers to obtain sensitive information through improper construction of CSV files.
CVE-2015-8509 can potentially lead to XSS attacks as it allows CSV data to be interpreted as JavaScript code by web browsers.