Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-0486
Description:Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-0486
BugTraq ID: 33581
http://www.securityfocus.com/bid/33581
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.html
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.html
http://secunia.com/advisories/34361




© 1998-2025 E-Soft Inc. All rights reserved.