VDB
CVE-2012-3981
CVE-2012-3981
PUBLISHED
CVSS 5 MEDIUM
Auth/Verify/LDAP.pm in Bugzilla 2.x and 3.x before 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 does not restrict the characters in a username, which might allow remote attackers to inject data into an LDAP directory via a crafted login attempt.
EPSS 0.60% · 69.9th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
0.60%
69.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mozilla | bugzilla | 2.21.1, 2.4, 2.6 |
| n/a | n/a | n/a |
Timeline
- Sep 4, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- 85072 vdb
- https://bugzilla.mozilla.org/show_bug.cgi?id=785470 url
- http://www.bugzilla.org/security/3.6.10/ url
- MDVSA-2013:066 vendor-advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=785112 url
- bugzilla-ldap-data-manipulation(78193) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2012-3981 advisory
- http://www.bugzilla.org/security/3.6.10 url