CVE-2006-5455

Publication date 23 October 2006

Last updated 17 July 2025


Ubuntu priority

Description

Cross-site request forgery (CSRF) vulnerability in editversions.cgi in Bugzilla before 2.22.1 and 2.23.x before 2.23.3 allows user-assisted remote attackers to create, modify, or delete arbitrary bug reports via a crafted URL.

Status

Package Ubuntu Release Status
bugzilla 9.10 karmic
Fixed 2.22.1-2
9.04 jaunty
Fixed 2.22.1-2
8.10 intrepid
Fixed 2.22.1-2
8.04 LTS hardy
Fixed 2.22.1-2
7.10 gutsy
Fixed 2.22.1-2
7.04 feisty
Fixed 2.22.1-2
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities