|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
Bugzilla contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the malicious user has any blessgroupset privileges (the ability to change only specific privileges for other users), and alters the <form> data. This flaw may lead to a loss of Integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
OSVDB:
Web Related
|
|
Solution |
Upgrade to version 2.14.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds. All Bugzilla users currently using version 2.15 checked out of cvs prior to 15 December 2001 should obtain the current cvs code.
|
|
Products |
|
Bugzilla
 |
2.14 |
|
|
|
|
Credit |
- funkysh - funkysh
sm.pl -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|