CVE-2008-2105

Publication date 7 May 2008

Last updated 17 July 2025


Ubuntu priority

Description

email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header. NOTE: since From headers are easily spoofed, this only crosses privilege boundaries in environments that provide additional verification of e-mail addresses.

Read the notes from the security team

Status

Package Ubuntu Release Status
bugzilla 8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
7.04 feisty
Not affected
6.06 LTS dapper
Not affected

Notes


kees

this really should be for bugzilla3 but it's not in intrepid yet


wgrant

our 2.x releases are too old, and 3.0.4 is too new.


Access our resources on patching vulnerabilities