Skip to main content

Bugzilla Multiple Vulnerabilities

Last Update Date: 13 Oct 2014 18:55 Release Date: 13 Oct 2014 3214 Views

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A security issue and some vulnerabilities have been identified in Bugzilla, which can be exploited by malicious users to disclose potentially sensitive information and by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions.

  1. An error within the flagmail email template can be exploited to disclose content of private comments.
  2. An error within the "confirm_create_account()" function (token.cgi) can be exploited to create account with administrator privileges.
  3. Certain input is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Impact

  • Cross-Site Scripting
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Bugzilla versions 4.0 through 4.0.14, 4.1.1 through 4.2.10, 4.3.1 through 4.4.5, and 4.5.1 through 4.5.5.

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 2.5.26, 3.2.6, or 3.3.5.

Vulnerability Identifier


Source


Related Link