Description
CRLF injection vulnerability in Bugzilla 2.17.1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 allows remote attackers to inject arbitrary e-mail headers via an attachment description in a flagmail notification.
References (7)
Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/74300
Patch x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=657158
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/45501
Vendor Advisory x_refsource_confirm
http://www.bugzilla.org/security/3.4.11/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/69035
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2011/dsa-2322
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/49042
Scores
EPSS
0.0152
EPSS Percentile
71.5%
Details
CWE
CWE-94
Status
published
Products (43)
mozilla/bugzilla
2.17.1
mozilla/bugzilla
2.17.3
mozilla/bugzilla
2.17.4
mozilla/bugzilla
2.17.5
mozilla/bugzilla
2.17.6
mozilla/bugzilla
2.17.7
mozilla/bugzilla
2.18 (4 CPE variants)
mozilla/bugzilla
2.18.1
mozilla/bugzilla
2.18.2
mozilla/bugzilla
2.18.3
... and 33 more
Published
Aug 09, 2011
Tracked Since
Feb 18, 2026