Bugzilla is prone to a user-impersonation vulnerability because it fails to properly handle email addresses.
Credit:
The information has been provided by Frederic Buclin,Max Kanat-Alexander,Byron Jones,Mario Gomes and James Kettle.
The original article can be found at: http://www.securityfocus.com/bid/51784/info
Vulnerable Systems:
* Red Hat Fedora 16
* Red Hat Fedora 15
* Mozilla Bugzilla 4.0.3
* Mozilla Bugzilla 4.0.2
* Mozilla Bugzilla 3.6.7
* Mozilla Bugzilla 3.6.6
* Mozilla Bugzilla 3.6.4
* Mozilla Bugzilla 3.6.1
* Mozilla Bugzilla 3.4.13
* Mozilla Bugzilla 3.4.12
* Mozilla Bugzilla 3.4.10
* Mozilla Bugzilla 3.4.7
* Mozilla Bugzilla 3.4.6
* Mozilla Bugzilla 3.4.5
* Mozilla Bugzilla 3.4.4
* Mozilla Bugzilla 3.4.3
* Mozilla Bugzilla 3.4.2
* Mozilla Bugzilla 3.4.1
* Mozilla Bugzilla 3.6.3
* Mozilla Bugzilla 3.6.2
* Mozilla Bugzilla 3.6
* Mozilla Bugzilla 3.4.9
* Mozilla Bugzilla 3.4.8
* Mozilla Bugzilla 3.4 rc1
* Mozilla Bugzilla 3.4