|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
Bugzilla contains a flaw that may allow a malicious user to overwrite arbitrary files. The problem is that the program creates temporary files in directories with insecure permissions and does not verify that the filename is unused. It is possible that the flaw may allow a malicious user to create a symlink from the showdependencygraph.cgi script and overwrite an arbitrary file, resulting in a loss of integrity or availability.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Input Manipulation,
Race Condition
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 2.16.3 (stable release) or 2.17.4 (development release) or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
Bugzilla
 |
2.16 |
2.10 |
2.12 |
2.14.x |
2.16.1 |
2.16.2 |
2.17 |
2.17.1 |
2.17.2 |
2.17.3 |
2.4 |
2.6 |
2.8 |
|
|
|
|
|
|
Credit |
- Jonathan Schatz - jon
vmware.com -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|