Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, generated insufficiently random numbers, resulting in all random tokens being the same, all CSRF protection being defeated, and the new attachment_base functionality being compromised.
242b54b1cddc091b8ac840990a5715422764ecd5ea5df5950cbb65e6eccd8af5