From 0c29bd76219ab35494f7cc202ffa071bc5006881 Mon Sep 17 00:00:00 2001 From: Reed Loden Date: Thu, 30 Aug 2012 20:27:36 +0200 Subject: Bug 785470: (CVE-2012-3981) [SECURITY] Missing escaping of the username can lead to LDAP injection r/a=LpSolit --- Bugzilla/Auth/Verify/LDAP.pm | 2 ++ 1 file changed, 2 insertions(+) (limited to 'Bugzilla/Auth') diff --git a/Bugzilla/Auth/Verify/LDAP.pm b/Bugzilla/Auth/Verify/LDAP.pm index cdc802ca0..0f10f9fbf 100644 --- a/Bugzilla/Auth/Verify/LDAP.pm +++ b/Bugzilla/Auth/Verify/LDAP.pm @@ -41,6 +41,7 @@ use Bugzilla::User; use Bugzilla::Util; use Net::LDAP; +use Net::LDAP::Util qw(escape_filter_value); use constant admin_can_create_account => 0; use constant user_can_create_account => 0; @@ -144,6 +145,7 @@ sub check_credentials { sub _bz_search_params { my ($username) = @_; + $username = escape_filter_value($username); return (base => Bugzilla->params->{"LDAPBaseDN"}, scope => "sub", filter => '(&(' . Bugzilla->params->{"LDAPuidattribute"} -- cgit v1.2.3-24-g4f1b