PT-2002-2178 · Mozilla · Bugzilla

Publicado

2002-10-28

·

Atualizado

2016-10-18

·

CVE-2002-1196

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Bugzilla versions 2.14.x through 2.14.3 Bugzilla versions 2.16.x through 2.16.0
Description: The issue arises in the editproducts.cgi script of Bugzilla when the usebuggroups feature is enabled and more than 47 groups are specified. It fails to properly calculate bit values for large numbers due to known features of Perl math, which can set multiple bits. This miscalculation grants extra permissions to users.
Recommendations: For Bugzilla versions 2.14.x through 2.14.3, update to version 2.14.4 or later. For Bugzilla versions 2.16.x through 2.16.0, update to version 2.16.1 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1196
DSA-173

Produtos afetados

Bugzilla