PT-2002-2178 · Mozilla · Bugzilla
Publicado
2002-10-28
·
Atualizado
2016-10-18
·
CVE-2002-1196
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Bugzilla versions 2.14.x through 2.14.3
Bugzilla versions 2.16.x through 2.16.0
Description:
The issue arises in the
editproducts.cgi script of Bugzilla when the usebuggroups feature is enabled and more than 47 groups are specified. It fails to properly calculate bit values for large numbers due to known features of Perl math, which can set multiple bits. This miscalculation grants extra permissions to users.Recommendations:
For Bugzilla versions 2.14.x through 2.14.3, update to version 2.14.4 or later.
For Bugzilla versions 2.16.x through 2.16.0, update to version 2.16.1 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bugzilla