7.5
CVSSv2

CVE-2009-0486

Published: 09/02/2009 Updated: 25/03/2009
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote malicious users to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla bugzilla 3.2.1

mozilla bugzilla 3.3.2

mozilla bugzilla 3.0.7