Bugzilla Multiple Vulnerabilities
Last Update Date:
13 Oct 2014 18:55
Release Date:
13 Oct 2014
4233
Views
RISK: Medium Risk
TYPE: Servers - Other Servers

A security issue and some vulnerabilities have been identified in Bugzilla, which can be exploited by malicious users to disclose potentially sensitive information and by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions.
- An error within the flagmail email template can be exploited to disclose content of private comments.
- An error within the "confirm_create_account()" function (token.cgi) can be exploited to create account with administrator privileges.
- Certain input is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Impact
- Cross-Site Scripting
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- Bugzilla versions 4.0 through 4.0.14, 4.1.1 through 4.2.10, 4.3.1 through 4.4.5, and 4.5.1 through 4.5.5.
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 2.5.26, 3.2.6, or 3.3.5.
Vulnerability Identifier
Source
Related Link
Share with